CVE-2025-10162
BaseFortify
Publication date: 2025-10-07
Last updated on: 2025-10-08
Assigner: WPScan
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| woocommerce | orderconvo | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before version 14. It does not properly validate the file paths for files to be downloaded, which allows an unauthenticated attacker to perform a path traversal attack and read or download arbitrary files from the server.
How can this vulnerability impact me? :
An attacker could exploit this vulnerability to access sensitive files on the server without authentication. This could lead to exposure of confidential information, potentially compromising the security and privacy of your system and data.