Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-49885

Опубликовано: 27 июн. 2025
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Drag and Drop Multiple File Upload (Pro) - WooCommerce: from n/a through 5.0.6.

EPSS

Процентиль: 33%
0.00126
Низкий

10 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
github
8 месяцев назад

Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Drag and Drop Multiple File Upload (Pro) - WooCommerce: from n/a through 5.0.6.

EPSS

Процентиль: 33%
0.00126
Низкий

10 Critical

CVSS3

Дефекты

CWE-434