What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects WR Price List Manager For Woocommerce: from n/a through <= 1.0.8.
Explanation of Vulnerability in Simple Terms
02Summary
WR Price List Manager For Woocommerce versions 1.0.8 and earlier allow authenticated users to upload files without restriction. An attacker with low-level site access can upload malicious files to execute code on the server. The vulnerability affects confidentiality, integrity, and availability of the entire site.
What an attacker can do
03Attacker Capabilities
Upload and execute malicious files on the server to run their own code.
Potential impact on your site
04Site Impact
Compromised site with potential data theft, defacement, malware installation, or complete takeover.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account on the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
January 15, 2025
CVE published
April 28, 2026
Record updated