CVE-2025-60248 | WPClever WPC Product Options for WooCommerce Plugin up to 1.8.6 on WordPress filename control
A vulnerability described as critical has been identified in WPClever WPC Product Options for WooCommerce Plugin up to 1.8.6 on WordPress. This vulnerability affects unknown code. Executing manipulation can lead to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability appears as CVE-2025-60248. The attack may be performed from remote. There is no available exploit.