CVE-2025-30835

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 98

Summary

CVE-2025-30835 is a newly identified vulnerability affecting Bastien Ho Accounting for WooCommerce. This issue stems from an improper control of filenames in PHP include/require statements, enabling PHP Local File Inclusion. Exploitation of this PHP Remote File Inclusion (RFI) vulnerability could lead to unauthorized access and potential data theft. The affected software versions range from not available through 1.6.8. It is crucial for users to update to the latest, secure version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Accounting For Woocommerce Plugin

Affected Vendors

  • WordPress