CVE-2025-39378
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-39378 is a filename vulnerability affecting Holest Engineering's Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light. The issue arises from an improper control of filename for include/require statements in PHP code, enabling an attacker to include local files through remote file inclusion. This vulnerability, classified as PHP Remote File Inclusion, can potentially lead to unauthorized access or data disclosure. The software versions from n/a through 2.4.37 are reportedly impacted. It is essential for users to update to the latest secure version as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.