PT-2025-38079 · Undefined · Undefined

Khaled Alenazi

·

Published

2025-09-16

·

Updated

2026-06-02

·

CVE-2025-10162

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin versions prior to 14
Description The plugin fails to validate the path of files intended for download. This allows an unauthenticated attacker to perform a path traversal attack, which is a method used to access files and directories that are stored outside the web root folder, resulting in the ability to read or download arbitrary files from the server.
Recommendations Update the plugin to version 14 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-10162

Affected Products

Undefined