CVE Details
Basic Information
| Title |
CVE-2025-4602 |
| Type |
cve |
| Published |
2025-05-24T04:15:28 |
| Last Seen |
2025-05-24T04:21:02 |
CVSS Information
| Base Score |
5.9 (MEDIUM) |
| Attack Vector |
NETWORK |
| Attack Complexity |
HIGH |
| Privileges Required |
NONE |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
HIGH |
| Integrity Impact |
NONE |
| Availability Impact |
NONE |
AI Analysis
| AI Description |
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5. This vulnerability allows unauthenticated attackers to read arbitrary files on the server, potentially exposing sensitive information. The issue arises from improper handling of user input in the get_file() function. |
| AI Severity |
Medium |
| Vendor |
eMagicOne |
| Product |
Store Manager for WooCommerce |
| Affected Version |
<=1.2.5 |
Additional Information
| CVE List |
CVE-2025-4602 |
| CWE List |
CWE-73 |
| Bulletin Family |
cve |
Description
The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions up to, and including, 1.2.5 via the get_file() function. This makes it possible…
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)
View Full CVE Details