CVE-2025-39557 PUBLISHED

WordPress Kadence WooCommerce Email Designer plugin <= 1.5.14 - Arbitrary File Upload vulnerability

Assigner: Patchstack
Reserved: 16.04.2025 Published: 16.04.2025 Updated: 16.04.2025

Unrestricted Upload of File with Dangerous Type vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Upload a Web Shell to a Web Server. This issue affects Kadence WooCommerce Email Designer: from n/a through 1.5.14.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor Ben Ritner - Kadence WP
Product Kadence WooCommerce Email Designer
Versions Default: unaffected
  • affected from n/a to 1.5.14 (incl.)

Solutions

Update the WordPress Kadence WooCommerce Email Designer plugin to the latest available version (at least 1.5.15).

Credits

  • Phan Trong Quan - VNPT Cyber Immunity (Patchstack Alliance) finder

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server