PT-2025-38079 · Undefined · Undefined
Khaled Alenazi
·
Published
2025-09-16
·
Updated
2026-06-02
·
CVE-2025-10162
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin versions prior to 14
Description
The plugin fails to validate the path of files intended for download. This allows an unauthenticated attacker to perform a path traversal attack, which is a method used to access files and directories that are stored outside the web root folder, resulting in the ability to read or download arbitrary files from the server.
Recommendations
Update the plugin to version 14 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined