CVE-2025-6439: WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Deletion
The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wcdpsavecanvasdesignajax' function in all versions up to, and including, 1.9.26. This makes it possible for unauthenticated attackers to delete all files in an arbitrary directory on the server, which can lead to remote code execution, data loss, or site unavailability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6439?
CVE-2025-6439 has a high severity rating due to the potential for arbitrary file deletion.
How do I fix CVE-2025-6439?
To fix CVE-2025-6439, update the WooCommerce Designer Pro plugin to version 1.9.27 or later.
Which versions of WooCommerce Designer Pro are affected by CVE-2025-6439?
CVE-2025-6439 affects all versions of WooCommerce Designer Pro up to and including version 1.9.26.
What types of attacks are possible due to CVE-2025-6439?
CVE-2025-6439 could allow attackers to delete arbitrary files on the server, leading to data loss or service disruptions.
Is the Pricom theme also affected by CVE-2025-6439?
Yes, the Pricom WordPress theme, which uses the WooCommerce Designer Pro plugin, is vulnerable as it relies on the affected plugin.