CVE 7.5 HIGH

OrderConvo < 14 - Unauthenticated Arbitrary File Read_CVE-2025-10162

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

Basic Information

ID CVE-2025-10162
Source WPScan
Published Oct 7, 2025 at 06:00
Modified Oct 7, 2025 at 14:14

Affected Product

Vendor Unknown
Product Admin and Customer Messages After Order for WooCommerce: OrderConvo
Affected Versions Unknown Admin and Customer Messages After Order for WooCommerce: OrderConvo 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.