---
id: CVE-2025-10754
title: >-
  The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in the zip upload
  functionality in all versions up to, and including, 1.0.1
summary: >-
  The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary
  file uploads due to missing file type validation in the zip upload
  functionality in all versions up to, and including, 1.0.1. This makes it
  possible for authentic…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10754'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/docodoco-store-locator/tags/1.0.1/includes/Admin/ZIP.php#L187
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/docodoco-store-locator/tags/1.0.1/includes/Admin/ZIP.php#L275
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/14759eb0-455f-4b7d-abab-4e4d89b32bb1?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00695
epssPercentile: 0.51474
ingestedAt: '2026-10-08T11:31:27.426Z'
---

## Overview

The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the zip upload functionality in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
