CVE-2025-60219
BaseFortify
Publication date: 2025-09-26
Last updated on: 2026-04-23
Assigner: Patchstack
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| harutheme | woocommerce_designer_pro | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in HaruTheme WooCommerce Designer Pro allows an attacker to upload a web shell to the web server due to unrestricted file upload of dangerous file types. This means malicious files can be uploaded without proper validation, potentially giving attackers control over the server.
How can this vulnerability impact me? :
The vulnerability can lead to full compromise of the affected web server, allowing attackers to execute arbitrary code, steal data, modify or delete information, and disrupt services. It poses a critical risk to the confidentiality, integrity, and availability of the system.