CVE-2025-31411
WordPress Linet ERP-Woocommerce Integration plugin <= 3.5.12 - Arbitrary File Read/Deletion vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Aribhour Linet ERP-Woocommerce Integration allows Path Traversal.This issue affects Linet ERP-Woocommerce Integration: from n/a through 3.5.12.
The Linet ERP-Woocommerce Integration Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 3.5.12. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Attackers can leverage the same functionality to read arbitrary files on the server.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-03-28 CVE Reserved
- 2025-04-10 CVE Published
- 2025-04-15 CVE Updated
- 2025-04-16 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
- CAPEC-126: Path Traversal
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linet Erp Woocommerce Integration Search vendor "Linet Erp Woocommerce Integration" | Linet Erp Woocommerce Integration Search vendor "Linet Erp Woocommerce Integration" for product "Linet Erp Woocommerce Integration" | >= 0.0.0 <= 3.5.12 Search vendor "Linet Erp Woocommerce Integration" for product "Linet Erp Woocommerce Integration" and version " >= 0.0.0 <= 3.5.12" | en |
Affected
|