The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-10-07 06:15
Updated : 2026-06-17 08:27
NVD link : CVE-2025-10162
Mitre link : CVE-2025-10162
CVE.ORG link : CVE-2025-10162
JSON object : View
Products Affected
No product.
CWE
No CWE.
