CVE-2025-29009 Details
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment Plugin for WooCommerce: from n/a through <= 1.2.3.
A vulnerability allowing unrestricted file uploads has been identified in the Webkul Medical Prescription Attachment Plugin for WooCommerce, affecting versions through 1.2.3. This vulnerability could be exploited to upload web shells to the server, potentially leading to unauthorized access or control over the website.
Users are advised to update the Webkul Medical Prescription Attachment Plugin for WooCommerce to the latest version. Patchstack has issued a virtual patch to block attacks targeting this vulnerability until an official fix is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2025CISA-ADP
Assessed Jul 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Webkul Medical Prescription Attachment Plugin | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Jul 16, 2025 | New CVE Received | [email protected] |
Volerion