PT-2025-29710 · Unknown+1 · Woocommerce+1

Michael Mazzolini

·

Published

2025-07-16

·

Updated

2025-07-21

·

CVE-2025-7359

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Counter live visitors for WooCommerce plugin for WordPress versions up to and including 1.3.6
Description The Counter live visitors for WooCommerce plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation within the wcvisitor get block function. This allows unauthenticated attackers to delete all files within a targeted directory, potentially leading to data loss or a denial of service.
Recommendations Update Counter live visitors for WooCommerce plugin for WordPress to a version later than 1.3.6.

Fix

DoS

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-7359

Affected Products

Counter Live Visitors For Woocommerce
Woocommerce