CVE-2025-39391
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-39391 is a filename control vulnerability affecting the Checkout Field Visibility plugin for WooCommerce, version n/a through 1.2.3. An attacker can exploit this PHP Remote File Inclusion (RFI) weakness to include local files, potentially leading to unauthorized access or data theft. The flaw occurs when the plugin fails to adequately sanitize user-supplied data used in include/require statements. This issue poses a significant risk for WordPress websites running the Checkout Field Visibility plugin and highlights the importance of timely software updates and input validation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.