PT-2025-41674 · WordPress · Woocommerce Designer Pro

Tonn

·

Published

2025-10-11

·

Updated

2025-10-16

·

CVE-2025-6439

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Designer Pro versions through 1.9.26
Description The WooCommerce Designer Pro plugin for WordPress is affected by an arbitrary file deletion issue. Insufficient file path validation in the wcdp save canvas design ajax function allows unauthenticated attackers to delete files in arbitrary directories on the server. This could lead to remote code execution, data loss, or site unavailability.
Recommendations Versions prior to and including 1.9.26 should be updated when a fix is available. As a temporary workaround, consider restricting access to the wcdp save canvas design ajax function until a patch is available.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-6439

Affected Products

Woocommerce Designer Pro