CVE-2025-39568
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 22
Summary
CVE-2025-39568 is a path traversal vulnerability affecting Arture B.V.'s StoreContrl Woocommerce plugin. The flaw arises from inadequate restriction of file paths, allowing unauthorized access to restricted directories. This issue potentially impacts Woocommerce installations from an undefined version up to 4.1.3. Successful exploitation could lead to data disclosure or even complete system compromise. It is recommended that users upgrade to a secure version of the plugin to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress