CVE-2023-5957

CVE-2023-5957: Ni Purchase Order(PO) For WooCommerce <= 1.2.1 - Admin+ File Upload to Remote Code Execution

Vendor Unknown
Product Ni Purchase Order(PO) For WooCommerce
Published January 8, 2024
Last update June 18, 2025

CVSS base score

What the vulnerability does

01Description

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

Key dates

02Disclosure timeline

January 8, 2024 CVE published
June 18, 2025 Record updated