PHP Local File Inclusion Vulnerability in PoloPag - Pix Automático para Woocommerce
CVE-2025-60189

7.5HIGH

What is CVE-2025-60189?

The PoloPag – Pix Automático para Woocommerce plugin contains a vulnerability that allows unauthorized PHP Local File Inclusion. This issue arises from improper control of filenames for the include/require statements within the PHP code, potentially leading to the execution of arbitrary code on the server. This vulnerability affects versions of the plugin up to and including 2.0.9, making it crucial for users to update and secure their installations to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

PoloPag &#8211; Pix Automático para Woocommerce <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k | Patchstack Bug Bounty Program
.