
WordPress TI WooCommerce Wishlist Plugin <= 2.9.2 Arbitrary File Upload
The WordPress plugin TI WooCommerce Wishlist version <= 2.9.2 is vulnerable to an unauthenticated arbitrary file upload vulnerability. This allows attackers to upload any file type, including executable PHP files, potentially leading to Remote Code Execution (RCE).
This vulnerability arises due to the lack of proper MIME-type and content validation on the upload endpoint /, allowing attackers to upload a file through a specially crafted multipart/form-data POST request.
product_id from homepage (data-tinv-wl-product)/wishlist/<key> for uploaded image pathresult.txtresult_wishlist.txtCredit: Patchstack Database
list.txt file with a list of target domains (one per line, without http).hinata.jpg) in the same folder.python3 CVE-2025-47577.py
list.txt:example.com
targetshop.org
store123.net
result.txt: List of successful uploaded image URLsresult_wishlist.txt: List of valid wishlist pages🔒 Disclaimer: This script is for educational and authorized testing purposes only.