Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 3.1.3.
Published: 2025-11-06
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper control of the filename supplied to PHP include/require statements in the WPC Product Options for WooCommerce plugin. This allows an attacker to specify arbitrary local file paths, enabling the inclusion of sensitive files or execution of malicious PHP code if the payload is placed within an includeable file. The impact can range from reading confidential server files to full remote code execution, depending on the attacker's ability to deliver a writable file or exploit existing writable PHP files.

Affected Systems

The vulnerability affects the WPC Product Options for WooCommerce plugin published by WPClever, specifically all releases up to and including version 3.1.3. Any WordPress installation using a vulnerable instance of this plugin is at risk.

Risk and Exploitability

The score of 7.5 on the CVSS scale indicates high severity, while the EPSS score of less than 1% suggests that the overall exploitation probability remains low at this time. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is through crafted input that the plugin passes directly to include/require calls, and it can be exploited by anyone who can influence that input, possibly including unauthenticated users unless mitigated by other access controls. Exploitation requires that the web server allows PHP to read files from the specified paths, and that the attacker can cause the plugin to include a payload or existing file.

Generated by OpenCVE AI on April 29, 2026 at 13:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WPC Product Options for WooCommerce plugin to the latest available version that removes the unsanitized include path handling
  • Whitelist acceptable file paths or disallow arbitrary file names in the plugin’s configuration to prevent inclusion of unintended files
  • If the plugin does not provide a configuration option, restrict the web server’s PHP include path and disable writing of PHP files in directories that could be included by the plugin

Generated by OpenCVE AI on April 29, 2026 at 13:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 1.8.6. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 3.1.3.
Title WordPress WPC Product Options for WooCommerce plugin <= 1.8.6 - Local File Inclusion vulnerability WordPress WPC Product Options for WooCommerce plugin <= 3.1.3 - Local File Inclusion vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpclever
Wpclever wpc Product Bundles For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpclever
Wpclever wpc Product Bundles For Woocommerce

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPClever WPC Product Options for WooCommerce wpc-product-options allows PHP Local File Inclusion.This issue affects WPC Product Options for WooCommerce: from n/a through <= 1.8.6.
Title WordPress WPC Product Options for WooCommerce plugin <= 1.8.6 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
Wpclever Wpc Product Bundles For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:44:42.723Z

Reserved: 2025-09-25T15:34:44.964Z

Link: CVE-2025-60248

cve-icon Vulnrichment

Updated: 2025-11-07T14:09:48.599Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:07.667

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-60248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:00:12Z

Weaknesses