CVE-2025-12835: Unknown Woomulti

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The WooMulti WordPress plugin through 17 does not validate a file parameter when deleting files, which could allow any authenticated users, such as subscriber to delete arbitrary files on the server.

Affected products

  • Unknown Woomulti: up to and including 1.7

Published 2025-12-12. Last modified 2026-10-07.