← Back to browse · API

CVE-2025-49885

Severity
CRITICAL
CVSS
10.0
EPSS
0.00348
Risk score
40.12
CISA KEV
No
PoC
No
Published
2025-06-27
Modified
2026-05-12
First seen
2026-08-07
Aliases
EUVD-2025-19288, GHSA-GV3G-5WRH-3X24
Products
CodeDropz:Drag and Drop Multiple File Upload (Pro) - WooCommerce 0 ≤5.0.6
Sources
euvd EUVD-2025-19288

Description

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-upload-wc-pro allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop Multiple File Upload (Pro) - WooCommerce: from n/a through <= 5.0.6.

References