CVE Details
Basic Information
| Title | CVE-2025-4603 |
|---|---|
| Type | cve |
| Published | 2025-05-24T04:15:30 |
| Last Seen | 2025-05-24T04:21:02 |
CVSS Information
| Base Score | 9.1 (CRITICAL) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AI Analysis
| AI Description | The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation. This vulnerability allows unauthenticated attackers to delete arbitrary files on the server, potentially leading to a complete system compromise. |
|---|---|
| AI Severity | Critical |
| Vendor | eMagicOne |
| Product | Store Manager for WooCommerce |
| Affected Version | All versions up to and including 1.0.0 |
Additional Information
| CVE List | CVE-2025-4603 |
|---|---|
| CWE List | CWE-73 |
| Bulletin Family | cve |
Description
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_file() function in all versions up…
CVSS Score Summary
Base Score: %!f(string=#) (CRITICAL)