ilmosys Open Close WooCommerce Store Path Traversal Vulnerability Allowing PHP Local File Inclusion

Vulnerability

A path traversal vulnerability has been identified in the ilmosys Open Close WooCommerce Store plugin, specifically in versions through 4.9.5. This vulnerability allows for PHP local file inclusion, which could enable a malicious actor to include and execute local files from the server where the WordPress site is hosted.

Impact

Exploitation of this vulnerability could lead to local file inclusion, allowing attackers to include and execute files from the server. This could be particularly dangerous if sensitive files, such as those containing database credentials, are accessed, potentially leading to a complete takeover of the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.