The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'uni_cpo_remove_file' function in all versions up to, and including, 4.9.60. This makes it possible for unauthenticated attackers to delete arbitrary attachments or files stored in Dropbox if the file path is known. The vulnerability was partially patched in version 4.9.60.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moomoo
Moomoo product Options And Price Calculation Formulas For Woocommerce – Uni Cpo (premium) Wordpress Wordpress wordpress |
|
| Vendors & Products |
Moomoo
Moomoo product Options And Price Calculation Formulas For Woocommerce – Uni Cpo (premium) Wordpress Wordpress wordpress |
Wed, 11 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'uni_cpo_remove_file' function in all versions up to, and including, 4.9.60. This makes it possible for unauthenticated attackers to delete arbitrary attachments or files stored in Dropbox if the file path is known. The vulnerability was partially patched in version 4.9.60. | |
| Title | Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) <= 4.9.60 - Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-11T16:47:37.821Z
Reserved: 2025-11-18T23:21:10.049Z
Link: CVE-2025-13391
Updated: 2026-02-11T16:47:34.320Z
Status : Awaiting Analysis
Published: 2026-02-11T17:16:06.500
Modified: 2026-02-11T18:06:04.010
Link: CVE-2025-13391
No data.