CVE-2025-60204: WordPress WooCommerce Store Toolkit plugin <= 2.4.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Josh Kohlbach WooCommerce Store Toolkit woocommerce-store-toolkit allows PHP Local File Inclusion.This issue affects WooCommerce Store Toolkit: from n/a through <= 2.4.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60204?
CVE-2025-60204 is classified as a high severity vulnerability due to its potential for remote file inclusion, which could lead to unauthorized access and system compromise.
How do I fix CVE-2025-60204?
To fix CVE-2025-60204, update the WooCommerce Store Toolkit to version 2.4.4 or later, which addresses the local file inclusion issue.
Which versions of WooCommerce Store Toolkit are affected by CVE-2025-60204?
CVE-2025-60204 affects WooCommerce Store Toolkit versions up to and including 2.4.3.
What type of attack does CVE-2025-60204 allow?
CVE-2025-60204 allows for PHP Local File Inclusion, enabling attackers to include unwanted files in the application.
Is CVE-2025-60204 specific to a particular plugin?
Yes, CVE-2025-60204 specifically affects the WooCommerce Store Toolkit by Josh Kohlbach.