CVE-2025-6440

LOWCVSS 9.8 ยท CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file uploads due to missing file type validation in the 'wcdp_save_canvas_design_ajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions ยท 2026-09-21: 109-21
Full discourse1 post
  • General Intels Daily@intels_daily

    ๐Ÿ”ด ๐—–๐—ฅ๐—œ๐—ง๐—œ๐—–๐—”๐—Ÿ ยท ๐—˜๐˜…๐—ฝ๐—น๐—ผ๐—ถ๐˜ ๐˜€๐—ฎ๐—น๐—ฒ ๐Ÿงฉ Product: ๐—ช๐—ผ๐—ผ๐—–๐—ผ๐—บ๐—บ๐—ฒ๐—ฟ๐—ฐ๐—ฒ ๐——๐—ฒ๐˜€๐—ถ๐—ด๐—ป๐—ฒ๐—ฟ ๐—ฃ๐—ฟ๐—ผ ๐Ÿ›ก๏ธ CVE-2025-6440 Threat actor lBaldwin is offering an exploit tool for CVE-2025-6440, a critical arbitrary file upload vulnerability affecting WooCommerce Designer Pro plugin versions 1.9.26 and earlier, allowing for remote code execution and site takeover. #ExploitSale #Exploit #ThreatIntel #CTI

    00000103
    596 followersView on X

Explore more