Unrestricted File Upload Vulnerability in ELEXtensions Product
CVE-2025-53213

9.9CRITICAL

What is CVE-2025-53213?

A vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping permits the upload of files with dangerous types, enabling potential misuse through malicious files. This vulnerability compromises the security of the affected product by allowing unauthorized access and manipulation of files, which could lead to further security breaches. Users are advised to update to the latest version to mitigate risks.

Affected Version(s)

ReachShip WooCommerce Multi-Carrier & Conditional Shipping <= 4.3.1

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.