CVE-2025-5746

Drag and Drop Multiple File Upload (Pro) - WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload

The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dnd_upload_cf7_upload_chunks() function in version 5.0 - 5.0.5 (when bundled with the PrintSpace theme) and all versions up to, and including, 1.7.1 (in the standalone version). This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The execution of PHP is disabled via a .htaccess file but is still possible in certain server configurations.


We have discovered 613 live websites that are affected by CVE-2025-5746.

Run a Free Instant Scan




Affected Software

Product  Drag And Drop Multiple File Upload For Woocommerce
Category Wordpress Plugins
Vulnerable Domains613 live websites (100% of Drag And Drop Multiple File Upload For Woocommerce install base)
Vulnerable Versions
  • from 0 through 1.7.1
  • from 5 through 5.0.5
Vulnerable Versions Count13 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Jul 2, 2025
  • Updated - Jul 2, 2025

Credits

  • Friderika Baranyai (finder)

Website Distribution by Country

Number of websites using CVE-2025-5746
United States179 websites



Germany61 websites
France52 websites
Spain43 websites
Cyprus41 websites
GB28 websites
South Africa17 websites
Italy16 websites
Poland13 websites
Netherlands12 websites

Website Distribution by TLD

Number of websites using CVE-2025-5746
.com274 websites
.es36 websites
.co.uk27 websites
.fr23 websites
.nl14 websites
.net12 websites
.com.au12 websites
.pl10 websites
.de10 websites
.it10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-5746

Top websites that are affected by CVE-2025-5746. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.*********.com United States***,***
*********.com United States***,***
********************.com United States***,***
********************.com United States*,***,***
*************.com United States*,***,***
***********.**.uk GB*,***,***
************.com Spain*,***,***
*********.cz Cyprus*,***,***
**************.org United States*,***,***
**************.**.uk GB*,***,***
See full domain list

FAQ

CVE-2025-5746 is Unrestricted Upload of File with Dangerous Type in Drag And Drop Multiple File Upload For Woocommerce
A total of 613 websites have been identified as vulnerable to CVE-2025-5746, based on global website indexing conducted by WebTechSurvey.
The Drag And Drop Multiple File Upload For Woocommerce is affected by the CVE-2025-5746 vulnerability.
Drag And Drop Multiple File Upload For Woocommerce versions up to and including 5.0.5 are vulnerable to CVE-2025-5746.