First published: Wed May 07 2025(Updated: )
Path Traversal vulnerability in ilmosys Open Close WooCommerce Store allows PHP Local File Inclusion. This issue affects Open Close WooCommerce Store: from n/a through 4.9.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ilmosys Open Close WooCommerce Store | <=4.9.5 | |
WordPress Open Close WooCommerce Store | <=4.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47649 is classified as a medium severity vulnerability, allowing potential local file inclusion.
To fix CVE-2025-47649, update the ilmosys Open Close WooCommerce Store plugin to the latest version beyond 4.9.5.
CVE-2025-47649 affects the ilmosys Open Close WooCommerce Store up to version 4.9.5.
In CVE-2025-47649, a path traversal vulnerability allows attackers to access files outside the intended directory.
Yes, CVE-2025-47649 can be exploited remotely by an attacker targeting the vulnerable plugin.