What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in ecomerciar Woocommerce Custom Profile Picture woo-custom-profile-picture allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Custom Profile Picture: from n/a through <= 1.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Woocommerce Custom Profile Picture plugin for WordPress allows authenticated users to upload files without proper validation. An attacker with a low-privilege account can upload malicious files, including PHP code, to execute arbitrary commands on the site. The vulnerability affects all versions up to 1.0 and impacts confidentiality, integrity, and availability of the entire WordPress installation.
What an attacker can do
03Attacker Capabilities
Upload and execute malicious files (such as PHP code) on the WordPress site.
Potential impact on your site
04Site Impact
Complete compromise of the WordPress site; attacker can read data, modify content, disable the site, or create admin accounts.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
October 23, 2024
CVE published
May 11, 2026
Record updated