Arbitrary File Upload Vulnerability in WooCommerce Refund And Exchange by WordPress
CVE-2025-6222
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 July 2025
What is CVE-2025-6222?
The WooCommerce Refund And Exchange with RMA theme for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation in the 'ced_rnx_order_exchange_attach_files' function. This flaw allows unauthenticated attackers to potentially upload malicious files to the server, which could facilitate remote code execution, compromising the security of the affected site. All versions up to and including 3.2.6 are impacted.
Affected Version(s)
WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet * <= 3.2.6