CVE-2025-12835: Unknown Woomulti
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as subscriber to delete arbitrary files on the server.
Affected products
- Unknown Woomulti: up to and including 1.7
Published 2025-12-12. Last modified 2026-10-07.