CVE-2025-1769: Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function
The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.0 via the downloadfile() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1769?
CVE-2025-1769 has a medium severity rating due to its potential for directory traversal vulnerabilities.
How do I fix CVE-2025-1769?
To fix CVE-2025-1769, update the Product Import Export for WooCommerce plugin to version 2.5.1 or later.
Who is affected by CVE-2025-1769?
CVE-2025-1769 affects all versions of the Product Import Export for WooCommerce plugin up to and including version 2.5.0.
What function is associated with CVE-2025-1769?
The directory traversal vulnerability in CVE-2025-1769 is associated with the download_file() function.
Is authentication required to exploit CVE-2025-1769?
Yes, CVE-2025-1769 can only be exploited by authenticated attackers with Administrator-level access.