External risk intelligence

WooCommerce Designer Pro Arbitrary File Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-6439

The vulnerability affects a WordPress plugin, which is a component of a web application. WordPress sites are frequently deployed as public-facing web services. The vulnerable function is reachable via AJAX endpoints, which are commonly exposed to the public internet to facilitate site functionality, making this surface typically accessible in standard web deployments.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in a WordPress plugin that may affect certain themes, allowing for the deletion of files on the server. This could potentially lead to unauthorized code execution, data loss, or website disruption. The main concern is to determine if your environment utilizes the affected plugin or theme.

  • Plugin allows unauthorized file deletion on servers.
  • Affects WordPress themes and associated plugins.
  • Confirm relevance and exposure to our environment.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by sending requests to a specific function within the WooCommerce Designer Pro plugin. This function, which handles saving canvas designs, does not properly validate file paths, allowing unauthenticated users to specify any file or directory on the server for deletion. Successful exploitation could lead to the removal of critical files, potentially resulting in remote code execution, significant data loss, or the complete unavailability of the website.

  • No authentication required.
  • Triggers by sending malicious AJAX requests.
  • Risk: File deletion, remote code execution, site unavailability.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to delete any file on the server. This is possible because the plugin does not properly validate file paths when saving design files, a function that can be accessed remotely.

  • Arbitrary files on the server.
  • Via an unauthenticated AJAX request.
  • Remote code execution or site unavailability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WooCommerce Designer Pro plugin, when used with the Pricom theme, is susceptible to arbitrary file deletion. Application owners, in conjunction with infrastructure and security teams, should prioritize identifying all instances of this plugin, assessing their business criticality and external reachability, and then coordinating remediation efforts.

  • Application and infrastructure owners
  • Verify plugin presence and reachability.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WooCommerce Designer Pro plugin?

It is a specialized WordPress plugin designed to add design and canvas customization features to online shops. It is often bundled with the Pricom - Printing Company & Design Services theme to help site visitors personalize their print orders. Because it integrates directly into the WordPress ecosystem, it processes data and handles file operations on your web server whenever users interact with design canvases.

What does CWE-22 mean for CVE-2025-6439?

CVE-2025-6439 is classified under CWE-22, which refers to Improper Limitation of a Pathname to a Restricted Directory, commonly known as Path Traversal. In plain terms, the plugin fails to check if a file path is safe before acting on it. Because it does not properly restrict where it can delete files, an attacker can manipulate the path to target important system files instead of the intended design data.

Do I need to be logged in to trigger this vulnerability?

No, authentication is not required to trigger this flaw. The vulnerability resides in an AJAX function meant to save design canvases, which is accessible to anyone visiting your site. Note that the bug is triggered by sending a specially crafted request to this endpoint; simply browsing your website or using the plugin's standard design tools in a normal way does not trigger the deletion of server files.

How do I know if this is relevant to my environment?

Check your WordPress installation for the WooCommerce Designer Pro plugin. According to Halo Surface Signal, this vulnerability is particularly relevant if your site is public-facing, as the affected AJAX endpoint is typically reachable over the internet. If your site uses this plugin and is accessible to the public, you should assume the risk is present regardless of whether you have custom themes or unique configurations.

How should I respond to this threat?

Start by identifying all WordPress sites in your environment that have the WooCommerce Designer Pro plugin installed. Once identified, evaluate their business use and determine if they are exposed to the public. Coordinate with your team to plan for updates or removal of the plugin. If a patch is not immediately available, consider disabling the plugin's functionality or taking the site offline if it handles sensitive operations until you can secure the server.

References