Cybersecurity researchers have uncovered a serious, unpatched security flaw affecting the TI WooCommerce Wishlist for WordPress that can be exploited by unauthenticated attackers to send arbitrary files.
See also: WordPress 'Motors' theme: Vulnerable to critical vulnerability

TI WooCommerce Wishlist, which has over 100,000 active installations, is a tool that allows online store customers to save favorite products for future purchase and share them on social media. The vulnerability is listed as CVE-2025-47577 and carries a CVSS score of 10.0, the highest possible. It affects all versions of the plugin up to and including 2.9.2, released on November 29, 2024.There is currently no patch.
The website security company said that the problem in the plugin is located in a function called “tinvwl_upload_file_wc_fields_factory” , which in turn uses the native WordPress function “wp_handle_upload” for validation, but bypasses critical control parameters by setting “test_form” and “test_type” to “false” .
The “test_type” parameter is used to check if the MIME (Multipurpose Internet Mail Extension) file type is the expected one, while the “test_form” parameter is used to verify if the $_POST['action'] variable contains the expected value. When “test_type” is set to false , file type validation is effectively bypassed, allowing any file type to be sent.
See also: Hackers exploit vulnerability in WordPress plugin OttoKit
It is worth noting that the vulnerable function is accessible via tinvwl_meta_wc_fields_factory or tinvwl_cart_meta_wc_fields_factory, which are only available when the WC Fields Factory is active.

This also means that successful exploitation of the vulnerability is only if the WC Fields Factory is installed and enabled on the WordPress site, and its integration is active in the TI WooCommerce Wishlist.
In a hypothetical attack scenario, a malicious user could upload a malicious PHP and achieve Remote Code Execution (RCE)by accessing the file directly via its URL.
Plugin developers are advised to avoid setting 'test_type' => false when using the wp_handle_upload(). In the absence of a patch available, users of the plugin are advised to disable it and delete it from their sites immediately.
See also: Scallywag: New ad-fraud campaign uses WordPress plugins
The vulnerability found in the TI WooCommerce Wishlist demonstrates how critical it is to properly utilize WordPress' built-in security mechanisms, such as file validation via wp_handle_upload(). Bypassing basic checks, such as test_type, opens the door to serious attacks, such as remote code execution (RCE).
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
