CVE-2025-10897
HIGH NUCLEIWooCommerce Designer Pro <1.9.28 - Info Disclosure
Title source: llmDescription
The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.
Nuclei Templates (1)
WooCommerce Designer Pro <= 1.9.28 - Arbitrary File Read
HIGHVERIFIEDby 0x_Akoko
Shodan:
http.html:"wc-designer-pro"
FOFA:
body="wc-designer-pro"
Scores
CVSS v3
8.6
EPSS
0.2258
EPSS Percentile
95.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (1)
JMA Plugins/WooCommerce Designer Pro
< 1.9.28
Published
Oct 31, 2025
Tracked Since
Feb 18, 2026