CVE-2025-1911
CVSS 3.1 Score 2.7 of 10 (low)
Details
Summary
CVE-2025-1911 is a vulnerability affecting the Product Import Export for WooCommerce plugin for WordPress. This issue allows authenticated attackers with Administrator-level access to delete arbitrary log files on the server. The vulnerability stems from insufficient file path validation in the admin_log_page() function, which is present up to and including version 2.5.0 of the plugin. This poses a significant risk, as attackers can manipulate the file path parameter to delete important system files or sensitive data, potentially leading to compromised websites or data loss.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.