CVE-2025-1911

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 73

Summary

CVE-2025-1911 is a vulnerability affecting the Product Import Export for WooCommerce plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to delete arbitrary log files on the server. The vulnerability stems from insufficient file path validation in the admin_log_page() function, which is present up to and including version 2.5.0 of the plugin. This poses a significant risk, as attackers can manipulate the file path parameter to delete important system files or sensitive data, potentially leading to compromised websites or data loss.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share