CVE-2025-10897
HIGH NUCLEIWooCommerce Designer Pro <1.9.28 - Info Disclosure
Title source: llmExploitation Summary
CVE-2025-10897 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.
Nuclei Templates (1)
WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read
HIGHVERIFIEDby 0x_Akoko
Shodan:
http.html:"wc-designer-pro"
FOFA:
body="wc-designer-pro"
References (2)
Core 2
Core References
Scores
CVSS v3
8.6
EPSS
0.1625
EPSS Percentile
95.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
JMA Plugins/WooCommerce Designer Pro
< 1.9.28
Published
Oct 31, 2025
Tracked Since
Feb 18, 2026