
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13391 is a Missing Authorization vulnerability in the Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress. Due to a missing capability check on the uni_cpo_remove_file function, unauthenticated attackers can delete arbitrary attachments or files stored in Dropbox if the file path is known. All versions up to and including 4.9.60 are affected, with only a partial patch applied in version 4.9.60. It carries a CVSS v3.1 base score of 5.8 (Medium) (Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization): the uni_cpo_remove_file function performs no capability or authentication check before executing file deletion operations. An attacker can invoke this function over the network without any credentials, supplying a known file path to target attachments or Dropbox-linked files. Because the scope is marked as Changed in the CVSS vector, the impact extends beyond the WordPress installation itself to third-party Dropbox storage. No authentication or user interaction is required, making exploitation straightforward for any network-accessible attacker (Red Hat CVE, CVE Feed).
Successful exploitation results in unauthorized deletion of arbitrary file attachments or Dropbox-stored files associated with WooCommerce product configurations, causing data loss for site operators and their customers. The integrity impact is low (file deletion rather than modification or exfiltration), and there is no direct confidentiality or availability impact to the WordPress host itself. However, destruction of product option files or customer-uploaded attachments can disrupt e-commerce operations and result in permanent data loss if backups are not maintained (Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.051%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The partial patch in version 4.9.60 means sites running that version may still be at risk depending on which file paths remain unprotected (Red Hat CVE, Vulners).
uni_cpo_remove_file function, supplying the known file path as a parameter — no authentication token or nonce is required due to the missing capability check./wp-admin/admin-ajax.php with action=uni_cpo_remove_file (or equivalent AJAX action name) originating from unknown or external IP addresses.Plugin users should update the Uni CPO (Premium) plugin beyond version 4.9.60, as the patch in that version is only partial. Monitor the plugin vendor's release channel for a fully remediated version that applies proper capability checks to the uni_cpo_remove_file function. As an interim workaround, administrators can restrict access to the WordPress AJAX endpoint via WAF rules or server-level controls to block unauthenticated requests invoking file removal actions. Regularly audit and back up Dropbox-linked files and WordPress attachments to minimize data loss risk (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."