CVE-2025-13391
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13391 is a Missing Authorization vulnerability in the Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress. Due to a missing capability check on the uni_cpo_remove_file function, unauthenticated attackers can delete arbitrary attachments or files stored in Dropbox if the file path is known. All versions up to and including 4.9.60 are affected, with only a partial patch applied in version 4.9.60. It carries a CVSS v3.1 base score of 5.8 (Medium) (Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the uni_cpo_remove_file function performs no capability or authentication check before executing file deletion operations. An attacker can invoke this function over the network without any credentials, supplying a known file path to target attachments or Dropbox-linked files. Because the scope is marked as Changed in the CVSS vector, the impact extends beyond the WordPress installation itself to third-party Dropbox storage. No authentication or user interaction is required, making exploitation straightforward for any network-accessible attacker (Red Hat CVE, CVE Feed).

Impact

Successful exploitation results in unauthorized deletion of arbitrary file attachments or Dropbox-stored files associated with WooCommerce product configurations, causing data loss for site operators and their customers. The integrity impact is low (file deletion rather than modification or exfiltration), and there is no direct confidentiality or availability impact to the WordPress host itself. However, destruction of product option files or customer-uploaded attachments can disrupt e-commerce operations and result in permanent data loss if backups are not maintained (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.051%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The partial patch in version 4.9.60 means sites running that version may still be at risk depending on which file paths remain unprotected (Red Hat CVE, Vulners).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Uni CPO (Premium) plugin by inspecting page source, HTTP headers, or using tools like WPScan to enumerate installed plugins and their versions (targeting ≤ 4.9.60).
  2. Identify file paths: Determine valid attachment or Dropbox file paths by browsing product pages, inspecting form submissions, or leveraging any exposed file references in the plugin's frontend output.
  3. Craft unauthenticated request: Send an HTTP request (e.g., POST or AJAX call) to the WordPress AJAX endpoint invoking the uni_cpo_remove_file function, supplying the known file path as a parameter — no authentication token or nonce is required due to the missing capability check.
  4. Achieve file deletion: The server processes the request and deletes the targeted attachment or Dropbox file, resulting in data loss for the affected site (Red Hat CVE, CVE Feed).

Indicators of compromise

  • Network: Unexpected unauthenticated POST requests to /wp-admin/admin-ajax.php with action=uni_cpo_remove_file (or equivalent AJAX action name) originating from unknown or external IP addresses.
  • Logs: WordPress access logs showing repeated calls to the AJAX endpoint for file removal without a valid session cookie or nonce; entries from IPs with no prior authenticated activity.
  • File System: Missing product option attachments or files that were previously present; gaps in Dropbox-linked file inventories corresponding to WooCommerce product configurations.
  • Application Logs: WooCommerce or plugin-level logs recording file deletion events without an associated authenticated user.

Mitigation and workarounds

Plugin users should update the Uni CPO (Premium) plugin beyond version 4.9.60, as the patch in that version is only partial. Monitor the plugin vendor's release channel for a fully remediated version that applies proper capability checks to the uni_cpo_remove_file function. As an interim workaround, administrators can restrict access to the WordPress AJAX endpoint via WAF rules or server-level controls to block unauthenticated requests invoking file removal actions. Regularly audit and back up Dropbox-linked files and WordPress attachments to minimize data loss risk (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management