PT-2026-41551 · WordPress · Woocommerce Csv Import Export
Published
2026-05-17
·
Updated
2026-05-17
·
CVE-2018-25325
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Woocommerce CSV Importer version 3.3.6
Description
A path traversal issue allows any registered user to delete arbitrary files. This occurs when unescaped filenames are submitted through the 'delete export file' AJAX action. An attacker can send POST requests containing directory traversal sequences in the
filename parameter to delete sensitive files, such as wp-config.php, located outside the intended export directory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Csv Import Export