Share
## https://sploitus.com/exploit?id=79541384-47A5-592D-A5A6-0CDB62D82608
๐Ÿงจ CVE-2025-6440 โ€“ WooCommerce Designer Pro Unrestricted File Upload

  Unauthenticated Arbitrary File Upload via wcdp_save_canvas_design_ajax
  WooCommerce Designer Pro plugin โ€“ Remote Code Execution (RCE)


---

## ๐Ÿ“– Description

The **WooCommerce Designer Pro** plugin for WordPress contains an **unauthenticated arbitrary file upload** vulnerability in the AJAX action `wcdp_save_canvas_design_ajax`. An attacker can upload any file (including malicious PHP scripts) without authentication, leading to **Remote Code Execution (RCE)**.

> **CVSS Score:** 9.8 (Critical)  
> **CWE:** CWE-434 (Unrestricted Upload of File with Dangerous Type)  
> **Attack Vector:** Network | **Complexity:** Low | **Privileges:** None

---

## โšก Affected Versions

| Plugin                        | Vulnerable Versions |
| :---------------------------- | :------------------ |
| WooCommerce Designer Pro      | All versions (unpatched) |

> **Note:** This vulnerability has been assigned **CVE-2025-6440**. The plugin may be discontinued. No patch is available.

---

## ๐Ÿ”ฌ Proof of Concept (PoC)

### ๐Ÿ Python Exploit

```bash
python CVE-2025-6440.py -u http://target.com/wordpress