
🚨 CVE-2025-4603: eMagicOne Store Manager for WooCo... Path traversal meets default creds (1:1) equals instant wp-config.php deletion and RCE - another WordPress plugin disast... https://zerodaysignal.com/vulnerability/CVE-2025-4603 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE‑2025‑4603 with technical details about a path traversal and default credential exploit that deletes wp-config.php and allows RCE, accompanied by a link to a vulnerability page. No patch, active exploitation, or false‑positive claim is mentioned.
