PT-2025-39159 · Woocommerce+1 · Woocommerce+2

Ren Voza

·

Published

2025-09-23

·

Updated

2025-09-24

·

CVE-2025-10412

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) versions through 4.9.54
Description The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress has an issue with file type validation. Specifically, the uni cpo upload file function allows unauthenticated attackers to upload arbitrary files to the server. This could potentially lead to remote code execution.
Recommendations Update to a version later than 4.9.54.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-10412

Affected Products

Uni Cpo
Woocommerce
Wordpress