PT-2025-45288 · Wpclever+1 · Wpc Product Options For Woocommerce+1

CVE-2025-60248

·

Published

2025-05-16

·

Updated

2025-11-06

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPC Product Options for WooCommerce versions prior to 3.1.3
Description The plugin contains a Local File Inclusion issue, which occurs when an application includes a file without properly validating the input, allowing an attacker to read or execute files on the server. Authenticated attackers with subscriber-level access and above can include and execute arbitrary files, potentially leading to the execution of PHP code. This flaw can be used to bypass access controls or obtain sensitive data, especially if images or other file types can be uploaded and subsequently included.
Recommendations Update WPC Product Options for WooCommerce to version 3.1.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60248

Affected Products

Wpc Product Options For Woocommerce
Wpc-Product-Options