CVE-2025-60203: WordPress Store Exporter plugin <= 2.7.6 - Local File Inclusion vulnerability
Published Nov 6, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach Store Exporter woocommerce-exporter allows PHP Local File Inclusion.This issue affects Store Exporter: from n/a through <= 2.7.6.
Affected Software
2 affected components
Josh Kohlbach Store Exporter<=2.7.6
WordPress Store Exporter<=2.7.6
Event History
Nov 6, 2025
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60203?
CVE-2025-60203 has a severity rating that indicates it allows remote file inclusion, posing a significant security risk.
2
How do I fix CVE-2025-60203?
To fix CVE-2025-60203, upgrade the Store Exporter plugin to a version above 2.7.6.
3
What versions of Store Exporter are affected by CVE-2025-60203?
CVE-2025-60203 affects Store Exporter versions up to and including 2.7.6.
4
What kind of vulnerability is CVE-2025-60203?
CVE-2025-60203 is classified as a PHP Remote File Inclusion vulnerability.
5
Who is the vendor affected by CVE-2025-60203?
The vendor affected by CVE-2025-60203 is Josh Kohlbach with the Store Exporter plugin.