CVE-2025-26933
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-26933 is a newly disclosed vulnerability affecting WC Place Order Without Payment, a plugin used in WooCommerce stores. The issue involves improper control of filenames in PHP include/require statements, enabling an attacker to conduct Local File Inclusion (LFI) attacks. By exploiting this vulnerability, an attacker can potentially gain unauthorized access to sensitive files on the affected system. This issue affects WC Place Order Without Payment versions 2.6.7 and below. It is recommended that users update their plugin to the latest version as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.