CVE-2025-60194: WordPress Premmerce Product Search for WooCommerce plugin <= 2.2.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows PHP Local File Inclusion.This issue affects Premmerce Product Search for WooCommerce: from n/a through <= 2.2.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60194?
CVE-2025-60194 is classified as a medium severity vulnerability due to its potential for local file inclusion exploits.
How do I fix CVE-2025-60194?
To fix CVE-2025-60194, upgrade to a patched version of Premmerce Product Search for WooCommerce beyond version 2.2.4.
What types of attacks can CVE-2025-60194 facilitate?
CVE-2025-60194 can facilitate local file inclusion attacks, allowing an attacker to execute arbitrary files on the server.
Which versions of Premmerce Product Search for WooCommerce are affected by CVE-2025-60194?
CVE-2025-60194 affects Premmerce Product Search for WooCommerce versions up to and including 2.2.4.
Is there a known exploit for CVE-2025-60194?
Yes, there are exploit techniques that can leverage CVE-2025-60194 for unauthorized access to local files.