The WooCommerce PPOM plugin for WordPress is not secure in versions up to and including 1.1. This means that unauthenticated attackers can upload files to the affected website’s server without restriction, which could allow them to run malicious code remotely.