CVE-2025-48148

CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper...

Affects 0 products across 2 vendors.

BCS6.27
CVSS 3.110.0
EPSS15.9%
Percentile97th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-434: Unrestricted Upload of File with Dangerous Type

Application allows file uploads without validating type, enabling upload of executable code or web shells.

Related Attack Patterns (CAPEC)
CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
via CWE-434

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in StoreKeeper for WooCommerce allows attackers to upload malicious files due to unrestricted file type checks, potentially leading to remote code execution.

BSID: BS-2025-GLOBAL-245364-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-48148?
A critical vulnerability in StoreKeeper for WooCommerce allows attackers to upload malicious files due to unrestricted file type checks, potentially leading to remote code execution.
What is the CVSS score for CVE-2025-48148?
CVE-2025-48148 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 15.9%.
Is CVE-2025-48148 actively exploited?
No confirmed active exploitation of CVE-2025-48148 as of 2026-05-30.
How do I remediate CVE-2025-48148?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-48148?
CVE-2025-48148 affects: Files, Woocommerce.
Vulnerability Details
CVE IDCVE-2025-48148
BSIDBS-2025-GLOBAL-245364-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2025-08-20
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeeper-for-woocommerce allows Using Malicious Files.This issue affects StoreKeeper for WooCommerce: from n/a through <= 14.4.4.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by uploading a malicious file with a dangerous file type (e.g., PHP) through the file upload functionality in the affected version of StoreKeeper for WooCommerce. If successful, the attacker can execute arbitrary code on the server, leading to unauthorized access, data theft, or further system compromise.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Files &mdash;
Woocommerce &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 348 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash6a4bc6379d5d85a98b427ba325387756635993aab015b8283fc50b5c6a0369ce4bd255bda859c159f5f839de44a429502b0e6122aee8f223f57ac3ed2ee34988
Related CVEs affecting Files
CVE-1999-0498 10.0 TFTP is not running in a restricted directory, allowing a remote attacker to ... CVE-1999-0561 10.0 IIS has the #exec function enabled for Server Side Include (SSI) files. CVE-1999-0937 10.0 BNBForm allows remote attackers to read arbitrary files via the automessage h... CVE-2025-23953 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite ... CVE-2025-32510 10.0 Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ova...
View all Files CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →