PT-2026-41551 · WordPress · Woocommerce Csv Import Export

Published

2026-05-17

·

Updated

2026-05-17

·

CVE-2018-25325

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Woocommerce CSV Importer version 3.3.6
Description A path traversal issue allows any registered user to delete arbitrary files. This occurs when unescaped filenames are submitted through the 'delete export file' AJAX action. An attacker can send POST requests containing directory traversal sequences in the filename parameter to delete sensitive files, such as wp-config.php, located outside the intended export directory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2018-25325

Affected Products

Woocommerce Csv Import Export