CVE-2025-1913
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 502
Summary
CVE-2025-1913 is a vulnerability affecting the Product Import Export for WooCommerce plugin for WordPress. This issue, present in all versions up to 2.5.0, allows authenticated attackers with Administrator-level access to inject PHP Objects via deserialization of untrusted input from the 'form_data' parameter. No Pop chain is present in the vulnerable software, but if one exists in an additional plugin or theme, the attacker may delete files, retrieve sensitive data, or execute code.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.