Published On: Mar 14, 2025 17:15
Advisory No: TZCERT-SA-25-0068
Source: Wordfence
Software Affected: workreap, woocommerce-products-filter
WordPress plugins are vulnerable to critical vulnerabilities. Exploitation of these vulnerabilities may allow an unauthenticated attacker to execute arbitrary code.
WordPress plugins workreap and woocommerce-products-filter are affected by the vulnerabilities tracked as CVE-2025-1315 and CVE-2025-1661 with CVSS scores of 9.8 each. The plugins are vulnerable due to improperly validating a user's identity and Local File Inclusion via the 'template' parameter of the woof_text_search AJAX action. The vulnerabilities allow unauthenticated attackers to bypass access controls, obtain sensitive data, or achieve code execution.
Successful exploitation of these vulnerabilities may allow the attackers to take control of the affected system.
WordPress has released security patches for these vulnerabilities. Users and administrators are encouraged to apply necessary updates.
A digest of Tanzania Computer Emergency Response Team coverage of cyber-security news across the globe.