---
id: CVE-2025-10897
title: >-
  The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary
  file read in all versions up to, and including, 1.9.28
summary: >-
  The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary
  file read in all versions up to, and including, 1.9.28. This makes it possible
  for unauthenticated attackers to read arbitrary files on the server, which can
  exp…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2025-10-31'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10897'
references:
  - url: >-
      https://codecanyon.net/item/woocommerce-designer-pro-cmyk-card-flyer/22027731
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/3a47cdeb-bd05-4e7e-99dc-dca67064182a?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.01947
epssPercentile: 0.79574
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/error-inside/CVE-2025-10897'
  nuclei:
    - CVE-2025-10897
  checkedAt: '2026-10-07T21:54:50.406Z'
exploitAvailable: true
ingestedAt: '2026-10-07T21:54:14.913Z'
---

## Overview

The WooCommerce Designer Pro theme for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.9.28. This makes it possible for unauthenticated attackers to read arbitrary files on the server, which can expose DB credentials when the wp-config.php file is read.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
