References https://cve.imfht.com/detail/CVE-2025-4336 https://www.nsfocus.net/vulndb/121445 https://cve.imfht.com/intel/404038 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/store-manager-connector/emagicone-store-manager-for-woocommerce-125-unauthenticated-arbitrary-file-upload-via-set-file https://github.com/d0n601/CVE-2025-4336 https://nvd.nist.gov/vuln/detail/CVE-2025-5058 https://afaghhosting.net/blog/cve-2025-4336-emagicone-store-manager-for-woocommerce-arbitrary-file-upload-vulnerability/ https://www.cve.org/CVERecord?id=CVE-2025-4336 https://cve.imfht.com/detail/CVE-2025-4336?lang=en
Related VulnerabilitiesPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL Injection旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2026-65761: Joomla Easy Store - SQL InjectionPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationHepta Platforms|Heptabase - Stored Cross-Site ScriptingPoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCCVE-2026-1115: parisneo/lollms < 2.2.0 - Authenticated Stored XSSPoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCds-store-file: DS_Store File - Exposed智慧物联网综合服务平台ListFileManager存在目录枚举漏洞PoCCVE-2026-27542: WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege Escalation