Vulnerability record · CVE-2014-9308 · published 15 January 2015
CVE-2014-9308: WP EasyCart plugin unrestricted file upload enables remote code execution
Wpeasycart · Wp Easycart
The WP EasyCart WordPress plugin before 3.0.9 contains an unrestricted file upload flaw in inc/amfphp/administration/banneruploaderscript.php. An authenticated user can upload a file with an executable extension and then request it directly from products/banners/, resulting in arbitrary code execution on the server.
Description
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in products/banners/.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution is achievable with a valid account, public exploit code exists, and EPSS is very high, though the CVSS base score is only 6.5 and the CVE is not in KEV.
What it is
The WP EasyCart WordPress plugin before 3.0.9 contains an unrestricted file upload flaw in inc/amfphp/administration/banneruploaderscript.php. An authenticated user can upload a file with an executable extension and then request it directly from products/banners/, resulting in arbitrary code execution on the server.
Impact
An attacker with a valid account can upload and execute arbitrary code, gaining control of the WordPress host and any data or services it can reach.
Attack surface
Reached over the network through the plugin's banner upload script; the CVSS vector (AV:N/AC:L/Au:S) indicates a valid authenticated session is required, and no user interaction beyond the upload and follow-up request is needed.
Exploitation
Public exploit code is referenced by Packet Storm, Exploit-DB and a vendor-independent advisory, and EPSS is 0.506 (98.9th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Update WP EasyCart to version 3.0.9 or later, which is the patched release per the plugin changelog.
- If immediate patching is not possible, disable or remove the plugin until it can be updated.
- Restrict upload directories such as products/banners/ so they cannot execute scripts (for example, deny PHP execution via web server configuration).
- Enforce strict file type and extension validation on all upload endpoints and store uploaded files outside the web root where feasible.
- Audit and limit accounts that can access the plugin's administration upload functionality.
Detection
- Monitor web server logs for POST requests to inc/amfphp/administration/banneruploaderscript.php followed by GET requests to files under products/banners/.
- Alert on newly created executable files (for example .php, .phtml, .php5) inside the products/banners/ directory.
- Review file upload events for extensions that do not match expected image types.
- Search for unexpected outbound connections or child processes spawned by the web server user after upload activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-9308 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9308), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.