Emagicone develops WordPress and WooCommerce plugins focused on e-commerce management, with its vulnerability profile concentrating in the Store Manager for WooCommerce product around file-handling weaknesses. The durable signal reflects the plugin's direct interaction with user-supplied file uploads and path traversal vectors, characterized by external control of file names and unrestricted file-type uploads typical of server-side file-management functionality. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emagicone over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-5058CRITICAL The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_image() function in all vers | May 24, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-4603CRITICAL The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in | May 24, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-4336CRITICAL The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_file() function in all versi | May 24, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-4602HIGH The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This | May 24, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emagicone.
Media articles that mention a CVE ID that affects a product developed by Emagicone — matched by CVE ID, not by vendor name.