CVE-2025-10897: WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10897?
CVE-2025-10897 is considered a critical vulnerability due to its potential for unauthorized access to sensitive files.
How do I fix CVE-2025-10897?
To fix CVE-2025-10897, upgrade the WooCommerce Designer Pro theme to version 1.9.29 or later.
Who is affected by CVE-2025-10897?
CVE-2025-10897 affects all versions of the WooCommerce Designer Pro theme up to and including 1.9.28.
What impact does CVE-2025-10897 have on my website?
The impact of CVE-2025-10897 could allow attackers to read sensitive files, such as database credentials, leading to further exploitation.
Is authentication required to exploit CVE-2025-10897?
No, CVE-2025-10897 can be exploited by unauthenticated attackers, making it particularly dangerous.