PT-2025-42696 · Unknown+1 · Woocommerce+1

Talal Nasraddeen

·

Published

2025-10-18

·

Updated

2026-02-13

·

CVE-2025-11391

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PPOM – Product Addons & Custom Fields for WooCommerce versions up to and including 33.0.15
Description The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is susceptible to arbitrary file uploads. This is due to a lack of file type validation within the image cropper functionality. Unauthenticated attackers can exploit this to upload arbitrary files to the server, potentially leading to remote code execution. The issue specifically affected users with the paid version of the software installed and activated.
Recommendations Update PPOM – Product Addons & Custom Fields for WooCommerce to version 33.0.16 or newer.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-11391

Affected Products

Ppom – Product Addons & Custom Fields For Woocommerce
Woocommerce