Arbitrary File Deletion in TicketBAI Facturas Plugin for WooCommerce
CVE-2025-4564

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 May 2025

What is CVE-2025-4564?

The TicketBAI Facturas para WooCommerce plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation through the 'delpdf' action. This vulnerability can be exploited by unauthenticated attackers to delete any file on the server, potentially leading to severe consequences such as remote code execution if critical files like wp-config.php are targeted. It is crucial for users of this plugin to apply necessary updates and pay close attention to security practices to safeguard their systems.

Affected Version(s)

TicketBAI Facturas para WooCommerce * <= 3.18

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexander Chikaylo
.