CVE-2025-26933

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 10, 2025
CWE ID 98

Summary

CVE-2025-26933 is a newly disclosed vulnerability affecting WC Place Order Without Payment, a plugin used in WooCommerce stores. The issue involves improper control of filenames in PHP include/require statements, enabling an attacker to conduct Local File Inclusion (LFI) attacks. By exploiting this vulnerability, an attacker can potentially gain unauthorized access to sensitive files on the affected system. This issue affects WC Place Order Without Payment versions 2.6.7 and below. It is recommended that users update their plugin to the latest version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share