Share
## https://sploitus.com/exploit?id=79541384-47A5-592D-A5A6-0CDB62D82608
๐งจ CVE-2025-6440 โ WooCommerce Designer Pro Unrestricted File Upload
Unauthenticated Arbitrary File Upload via wcdp_save_canvas_design_ajax
WooCommerce Designer Pro plugin โ Remote Code Execution (RCE)
---
## ๐ Description
The **WooCommerce Designer Pro** plugin for WordPress contains an **unauthenticated arbitrary file upload** vulnerability in the AJAX action `wcdp_save_canvas_design_ajax`. An attacker can upload any file (including malicious PHP scripts) without authentication, leading to **Remote Code Execution (RCE)**.
> **CVSS Score:** 9.8 (Critical)
> **CWE:** CWE-434 (Unrestricted Upload of File with Dangerous Type)
> **Attack Vector:** Network | **Complexity:** Low | **Privileges:** None
---
## โก Affected Versions
| Plugin | Vulnerable Versions |
| :---------------------------- | :------------------ |
| WooCommerce Designer Pro | All versions (unpatched) |
> **Note:** This vulnerability has been assigned **CVE-2025-6440**. The plugin may be discontinued. No patch is available.
---
## ๐ฌ Proof of Concept (PoC)
### ๐ Python Exploit
```bash
python CVE-2025-6440.py -u http://target.com/wordpress