CVE-2025-47577 is an unrestricted file upload vulnerability in the TI WooCommerce Wishlist WordPress plugin affecting versions up to and including 2.9.2. According to the provided content, the flaw allows an unauthenticated attacker to upload a file with a dangerous type, including a web shell, to the target web server. The issue is described as an arbitrary file upload condition in which attacker-controlled content can be written into a web-accessible uploads location, with detection logic referencing artifacts under /wp-content/uploads/product_addons_uploads/. The available content does not identify the exact vulnerable function or patch diff, but it does indicate that exploitation involves a multipart upload workflow and can be validated by retrieving a resulting wishlist URL that exposes the uploaded artifact.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit for CVE-2025-47577, a vulnerability in the TI WooCommerce Wishlist WordPress plugin (versions <= 2.9.2). The main file, CVE-2025-47577.py, is a Python script that allows an attacker to upload an arbitrary local file to a vulnerable WordPress site by sending a crafted multipart/form-data POST request to the wishlist endpoint. The script is configurable via command-line arguments for the target host, port, protocol (HTTP/HTTPS), base path, and product ID. The README provides usage instructions, affected versions, and patch guidance. The exploit demonstrates the vulnerability but does not include a weaponized or post-exploitation payload. The main attack vector is network-based, targeting a web application endpoint. The script is a standalone proof-of-concept and not part of a larger framework.
This repository contains a Python proof-of-concept exploit for CVE-2025-47577, targeting the WordPress TI WooCommerce Wishlist plugin (versions <= 2.9.2). The exploit automates the process of uploading an arbitrary file (such as an image or a PHP webshell) to vulnerable WordPress sites. It reads a list of target domains from 'list.txt', retrieves a required product_id from each target's homepage, and then crafts a multipart/form-data POST request to the main site endpoint to upload the file. After uploading, it parses the JSON response to extract the wishlist URL, checks the wishlist page for the uploaded file's path, and saves the URLs of successful uploads to 'result.txt' and wishlist pages to 'result_wishlist.txt'. The exploit leverages a lack of proper file validation in the plugin, potentially allowing remote code execution if a PHP file is uploaded. The repository consists of the main exploit script (CVE-2025-47577.py) and a detailed README explaining the vulnerability, usage instructions, and output files. No hardcoded IPs or domains are present; targets are user-supplied via 'list.txt'.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An arbitrary file upload vulnerability affecting the TI WooCommerce Wishlist WordPress plugin through version 2.9.2.
A previously disclosed unauthenticated remote code execution vulnerability affecting the same developer's software.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.