Unrestricted File Upload Vulnerability in StoreKeeper for WooCommerce by StoreKeeper B.V.
CVE-2025-48148
10CRITICAL
What is CVE-2025-48148?
The StoreKeeper for WooCommerce plugin developed by StoreKeeper B.V. is susceptible to an unrestricted file upload vulnerability, enabling attackers to upload and execute malicious files. This vulnerability compromises the security of WooCommerce stores by allowing unauthorized file types to be uploaded. Users of versions n/a to 14.4.4 should take immediate actions to secure their installations against potential exploitation, as failure to address this issue could lead to severe consequences for store operations and customer data.
Affected Version(s)
StoreKeeper for WooCommerce <= 14.4.4