CVE-2025-60248: WordPress WPC Product Options for WooCommerce plugin <= 3.1.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 3.1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60248?
CVE-2025-60248 has been classified with a critical severity due to its potential for PHP local file inclusion, allowing attackers to execute arbitrary files.
How do I fix CVE-2025-60248?
To mitigate CVE-2025-60248, update WPC Product Options for WooCommerce to the latest version beyond 1.8.6.
What software is affected by CVE-2025-60248?
CVE-2025-60248 affects WPC Product Options for WooCommerce versions up to and including 1.8.6.
Can CVE-2025-60248 lead to remote code execution?
Yes, CVE-2025-60248 can lead to remote code execution if an attacker successfully exploits the local file inclusion vulnerability.
Is there a known exploit for CVE-2025-60248?
Yes, CVE-2025-60248 has known exploits that leverage the vulnerability to include and execute local files on affected systems.