CVE-2025-39391

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 98

Summary

CVE-2025-39391 is a filename control vulnerability affecting the Checkout Field Visibility plugin for WooCommerce, version n/a through 1.2.3. An attacker can exploit this PHP Remote File Inclusion (RFI) weakness to include local files, potentially leading to unauthorized access or data theft. The flaw occurs when the plugin fails to adequately sanitize user-supplied data used in include/require statements. This issue poses a significant risk for WordPress websites running the Checkout Field Visibility plugin and highlights the importance of timely software updates and input validation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share