S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 11, 2026

CVE-2025-47577 Scanner

CVE-2025-47577 Scanner - Arbitrary File Upload vulnerability in TI WooCommerce Wishlist

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-47577
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Unrestricted Upload of File with Dangerous Type vulnerability in templateinvaders TI WooCommerce Wishlist ti-woocommerce-wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a through <= 2.9.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
TI WooCommerce Wishlistby templateinvaders
0
Updated Aug 22, 2026View on NVD →
Detail

The TI WooCommerce Wishlist plugin is widely used by online merchants who integrate their WordPress platforms with additional functionalities to engage more with their customers. It allows users to create wishlists for easier shopping experiences on WooCommerce sites. The plugin is typically implemented by online businesses to enhance customer interaction, offering personalized merchandising strategies. Its popularity among the e-commerce community is notable, especially among WordPress-powered stores aiming to improve usability and customer retention. Despite its utility, vulnerabilities may arise if there is a lack of updates or security checks, commonly exploited due to the widespread usage of the Woocommerce and WordPress ecosystem.

An arbitrary file upload vulnerability exists when an application does not sufficiently verify user-uploaded files, allowing them to upload any type of file to a server. In the case of TI WooCommerce Wishlist, the lack of proper file type validation can lead to malicious file uploads. Attackers can exploit this to upload web shells, which provide a backdoor into the server. Such unrestrained file uploads can lead to significant security risks, including the execution of arbitrary code by the attackers. Unauthorized individuals can exploit the plugin's inadequacies to upload potentially harmful files, circumventing security with ease as no special privileges are required. This poses a critical threat if not mitigated promptly.

The vulnerability is primarily due to insufficient validation of user input where file uploads occur. Specifically, attackers can upload a file through the `form[file]` parameter, which the system processes without stringent checks on file types. TI WooCommerce Wishlist plugin processes these files without properly restricting the file format, content, or size. The uploaded file reaches the server's uploads directory, a critical endpoint that should be protected more rigorously. Such weaknesses are often exploited using crafted requests that bypass normal authentication or file management routines, allowing attackers entry. The misconfiguration in the plugin allows the exploitation of other vulnerabilities like remote code execution once a malicious file is in place.

Successful exploitation of this vulnerability may lead to severe consequences, including unauthorized access and control over the server. An attacker who uploads a malicious script could execute arbitrary code, stealing sensitive data, launching further attacks, or disrupting server operations. It could also lead to data breaches involving customer information stored on the platform. Consequently, this vulnerability enhances the risk of full server compromise, potentially allowing attackers to control all aspects and data of the affected site. With such a vulnerability unchecked, businesses may face significant reputational and financial damage.

REFERENCES

Solution Advice
  • Upgrade TI WooCommerce Wishlist to version 2.10.0 or later to patch the vulnerability and secure your platform from unauthorized file uploads.
  • Restrict file upload types and apply validation checks to ensure only non-executable files are accepted by the system.
  • Implement security best practices by periodically reviewing server settings and file directories for unusual activity or unauthorized files.
  • Conduct regular code audits and employ security plugins specializing in detecting configuration errors and vulnerabilities in WordPress plugins.
  • Maintain backups and establish an incident response plan to quickly rectify any breaches resulting from such vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.