Arbitrary File Upload Vulnerability in StoreEngine eCommerce Plugin for WordPress
CVE-2025-9216
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2025
What is CVE-2025-9216?
The StoreEngine eCommerce Plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation in its import() function. This issue exists in all versions up to and including 1.5.0, allowing authenticated users with Subscriber-level access and above to upload malicious files onto the server hosting the affected site. Such uploads could enable remote code execution, posing significant security risks to WordPress installations utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
StoreEngine β Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More * <= 1.5.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved