Vulnerability record · CVE-2021-25003 · published 14 March 2022
CVE-2021-25003: WPCargo Track & Trace plugin unauthenticated PHP file write RCE
Wptaskforce · Wpcargo Track \& Trace
The WPCargo Track & Trace WordPress plugin before 6.9.0 ships a file that lets unauthenticated attackers write a PHP file anywhere on the web server. Because the written file is executable PHP, this turns into remote code execution on the host. It matters because the plugin is reachable without credentials and the flaw is trivially exploitable.
Description
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a 9.8 CVSS score and high EPSS probability makes this an urgent patch.
What it is
The WPCargo Track & Trace WordPress plugin before 6.9.0 ships a file that lets unauthenticated attackers write a PHP file anywhere on the web server. Because the written file is executable PHP, this turns into remote code execution on the host. It matters because the plugin is reachable without credentials and the flaw is trivially exploitable.
Impact
An attacker gains arbitrary PHP code execution on the web server, which typically means full control of the WordPress site and the ability to pivot to the underlying host. No confidentiality, integrity or availability limit is implied by the CVSS vector.
Attack surface
Reached over the network through the vulnerable plugin file; the CVSS vector shows no privileges required and no user interaction, so it is unauthenticated and remotely triggerable. No specific endpoint path is given in the record.
Exploitation
Not listed in CISA KEV, but EPSS is 0.56148 (99th percentile) and both references carry an Exploit tag, indicating public exploit material exists and exploitation is likely.
What to do
- Update WPCargo Track & Trace to 6.9.0 or later immediately.
- If patching is not possible, disable or remove the plugin until it can be updated.
- Block or restrict access to the plugin's PHP files at the web server or WAF layer.
- Enforce the principle of least privilege on the web server user and disable PHP execution in upload and writable directories.
- Audit the web root for unexpected PHP files and remove any that are not part of a known deployment.
Detection
- Monitor the web root and upload directories for newly created or modified PHP files.
- Alert on HTTP requests to WPCargo plugin paths that return 200 and precede file creation events.
- Review web server logs for POST requests to plugin endpoints from unauthenticated clients.
- Scan for webshell indicators and unexpected outbound connections from the web server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wpscan.com/vulnerability/5c21ad35-b2fb-4a51-858f-8ffff685de4a | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/5c21ad35-b2fb-4a51-858f-8ffff685de4a | ExploitThird Party Advisory |
Track CVE-2021-25003 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25003), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.