Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through <= 1.2.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository consists of one standalone Python script, CVE-2025-29009.py, rather than a framework module. It is an operational bulk/single-target exploit for CVE-2025-29009 affecting the Webkul WooCommerce Product Addons (wkwcpa) WordPress plugin. The script accepts either one URL or a target list, normalizes targets, and runs a configurable number of worker threads. For each target it requests likely storefront/product pages, searches page content for the JavaScript object wkwcpaFrontObj, and extracts the AJAX URL and nonce needed by the plugin. It then uses the vulnerable AJAX upload path to submit an operator-provided PHP shell and validates success through a configurable response signature. TLS certificate verification is deliberately disabled, proxy bypass is forced with NO_PROXY=*, and successful uploaded-shell URLs are written to shells.txt. No shell code is embedded in the repository: payload behavior depends on the local PHP file selected by the operator.
This repository is a small standalone Python exploit for CVE-2025-29009 affecting the Webkul Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 on WordPress. The repo contains one executable script (CVE-2025-29009.py), a README with exploitation details and usage instructions, and a license file. The exploit is not a framework module; it is a threaded mass-exploitation utility. Its workflow is: read target URLs from list.txt, request likely public frontend pages to find the JavaScript object wkwcpaFrontObj, extract ajaxUrl and ajaxNonce, submit a multipart POST using action=wkwcpa_handle_prescription_session and the file field wkwc_pa_prescription_attachment[], parse the JSON response to recover the uploaded file URL, request that URL to verify execution via a user-supplied signature string, and save successful shell URLs to shells.txt. Primary capability is unauthenticated arbitrary file upload leading to remote code execution when the operator supplies a PHP web shell. The included README demonstrates a simple payload using system($_GET['cmd']);. The script supports multithreading, basic status tracking, and success/failure reporting, making it suitable for scanning multiple WordPress targets. No hardcoded victim infrastructure, C2, or external callback domains are present; endpoints are derived from operator-provided target URLs and the target site's own exposed AJAX URL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.