CVE-2025-47577
CRITICAL 10.0EPSS 4.6%
Unrestricted Upload of File with Dangerous Type vulnerability in TemplateInvaders TI WooCommerce Wishlist allows Upload a Web Shell to a Web Server.This issue affects TI WooCommerce Wishlist: from n/a before 2.10.0.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 4.64% chance of exploitation in the next 30 days, 91th percentile
- Nuclei
- high · CWE-434
- Published
- 2025-05-19
- Updated
- 2026-05-12
Proof-of-concept exploits (2)
- Yucaerin/CVE-2025-475774★ · 2025-05-30
- sug4r-wr41th/CVE-2025-475770★ · 2025-06-25