CVE-2025-60219: WordPress WooCommerce Designer Pro Plugin <= 1.9.24 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro allows Upload a Web Shell to a Web Server. This issue affects WooCommerce Designer Pro: from n/a through 1.9.24.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allows Upload a Web Shell to a Web Server.This issue affects WooCommerce Designer Pro: from n/a through <= 1.9.24.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60219?
CVE-2025-60219 is considered a high severity vulnerability due to its potential to allow attackers to upload a web shell to the server.
How do I fix CVE-2025-60219?
To fix CVE-2025-60219, update HaruTheme WooCommerce Designer Pro to the latest version beyond 1.9.24.
What are the impacts of CVE-2025-60219?
The impacts of CVE-2025-60219 include unauthorized access to the server, potential data breaches, and the ability for attackers to execute malicious scripts.
Which versions are affected by CVE-2025-60219?
CVE-2025-60219 affects all versions of HaruTheme WooCommerce Designer Pro up to and including 1.9.24.
Who is the vendor associated with CVE-2025-60219?
The vendor associated with CVE-2025-60219 is HaruTheme.