PT-2025-50918 · WordPress · Woomulti

Khaled Alenazi

·

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-12835

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooMulti WordPress plugin versions through 17
Description The plugin does not properly check a file parameter during file deletion, potentially allowing authenticated users, even those with limited privileges like subscribers, to delete any file on the server. The affected API endpoint is not specified. The vulnerable parameter is not specified. The vulnerable function is not specified.
Recommendations Update WooMulti WordPress plugin to a version later than 17.

Exploit

Fix

Related Identifiers

CVE-2025-12835

Affected Products

Woomulti