Article & News

Day: June 1, 2025

Uncategorized
Critical Unauthenticated File Upload Vulnerability in TI WooCommerce Wishlist Plugin (CVE-2025-47577)

A critical vulnerability has been discovered in the popular TI WooCommerce Wishlist WordPress plugin, which affects all versions up to 2.9.2. This security flaw allows unauthenticated attackers to upload arbitrary files, including malicious PHP shells, and fully compromise the target server.

The vulnerability, tracked as CVE-2025-47577, carries a maximum CVSS score of 10.0.