/Vulnerability Library

WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read

CVE-2025-10897
Verified

Description

WooCommerce Designer Pro theme for WordPress <= 1.9.28 contains an arbitrary file read vulnerability caused by improper input validation, letting unauthenticated attackers read arbitrary files including sensitive configuration files, exploit requires no authentication.

Severity

High

CVSS Score

8.6

Exploit Probability

2%

Published Date

April 23, 2026

Template Author

0x_akoko

CVE-2025-10897.yaml
8.6Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE ID:
cve-2025-10897
CWE ID:
cwe-22

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wc-designer-pro/woocommerce-designer-pro-1928-unauthenticated-arbitrary-file-readhttps://nvd.nist.gov/vuln/detail/CVE-2025-10897

Remediation Steps

Update to the latest version beyond 1.9.28.