CVE Details
Basic Information
| Title |
CVE-2025-4336 |
| Type |
cve |
| Published |
2025-05-24T04:15:27 |
| Last Seen |
2025-05-24T04:21:02 |
CVSS Information
| Base Score |
8.1 (HIGH) |
| Attack Vector |
NETWORK |
| Attack Complexity |
HIGH |
| Privileges Required |
NONE |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
HIGH |
| Integrity Impact |
HIGH |
| Availability Impact |
HIGH |
AI Analysis
| AI Description |
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation. This allows unauthenticated attackers to upload malicious files, potentially leading to remote code execution or other server compromises. |
| AI Severity |
High |
| Vendor |
eMagicOne |
| Product |
Store Manager for WooCommerce |
| Affected Version |
All versions up to,… |
Additional Information
| CVE List |
CVE-2025-4336 |
| CWE List |
CWE-434 |
| Bulletin Family |
cve |
Description
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versions up to,…
CVSS Score Summary
Base Score: %!f(string=#) (HIGH)
View Full CVE Details