PT-2026-2809 · Woosaai · Integration Opvius Ai For Woocommerce

Published

2026-01-14

·

Updated

2026-01-14

·

CVE-2025-14301

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the
process table bulk actions()
function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the
wsaw-log[]
POST parameter, which can be leveraged to delete critical files like
wp-config.php
or read sensitive configuration files.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-14301

Affected Products

Integration Opvius Ai For Woocommerce