Arbitrary File Upload Vulnerability in StoreEngine eCommerce Plugin for WordPress
CVE-2025-9216
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2025
What is CVE-2025-9216?
The StoreEngine eCommerce Plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation in its import() function. This issue exists in all versions up to and including 1.5.0, allowing authenticated users with Subscriber-level access and above to upload malicious files onto the server hosting the affected site. Such uploads could enable remote code execution, posing significant security risks to WordPress installations utilizing this plugin.
Affected Version(s)
StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More * <= 1.5.0