← Vulnerability feed

Vulnerability record · CVE-2021-25003 · published 14 March 2022

CVE-2021-25003: WPCargo Track & Trace plugin unauthenticated PHP file write RCE

Wptaskforce · Wpcargo Track \& Trace

The WPCargo Track & Trace WordPress plugin before 6.9.0 ships a file that lets unauthenticated attackers write a PHP file anywhere on the web server. Because the written file is executable PHP, this turns into remote code execution on the host. It matters because the plugin is reachable without credentials and the flaw is trivially exploitable.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0% CWE-94 · Code injectionCWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score and high EPSS probability makes this an urgent patch.

What it is

The WPCargo Track & Trace WordPress plugin before 6.9.0 ships a file that lets unauthenticated attackers write a PHP file anywhere on the web server. Because the written file is executable PHP, this turns into remote code execution on the host. It matters because the plugin is reachable without credentials and the flaw is trivially exploitable.

Impact

An attacker gains arbitrary PHP code execution on the web server, which typically means full control of the WordPress site and the ability to pivot to the underlying host. No confidentiality, integrity or availability limit is implied by the CVSS vector.

Attack surface

Reached over the network through the vulnerable plugin file; the CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable. No specific endpoint path is given in the record.

Exploitation

Not listed in CISA KEV, but EPSS is 0.56148 (99th percentile) and both references carry an Exploit tag, indicating public exploit material exists and exploitation is likely.

What to do

  • Update WPCargo Track & Trace to 6.9.0 or later immediately.
  • If patching is not possible, disable or remove the plugin until it can be updated.
  • Block or restrict access to the plugin's PHP files at the web server or WAF layer.
  • Enforce the principle of least privilege on the web server user and disable PHP execution in upload and writable directories.
  • Audit the web root for unexpected PHP files and remove any that are not part of a known deployment.

Detection

  • Monitor the web root and upload directories for newly created or modified PHP files.
  • Alert on HTTP requests to WPCargo plugin paths that return 200 and precede file creation events.
  • Review web server logs for POST requests to plugin endpoints from unauthenticated clients.
  • Scan for webshell indicators and unexpected outbound connections from the web server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25003 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2021-25003), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.