Unrestricted File Upload Vulnerability in StoreKeeper for WooCommerce by StoreKeeper B.V.
CVE-2025-48148

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-48148?

The StoreKeeper for WooCommerce plugin developed by StoreKeeper B.V. is susceptible to an unrestricted file upload vulnerability, enabling attackers to upload and execute malicious files. This vulnerability compromises the security of WooCommerce stores by allowing unauthorized file types to be uploaded. Users of versions n/a to 14.4.4 should take immediate actions to secure their installations against potential exploitation, as failure to address this issue could lead to severe consequences for store operations and customer data.

Affected Version(s)

StoreKeeper for WooCommerce <= 14.4.4

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.