The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
History

Mon, 06 Oct 2025 22:45:00 +0000

Type Values Removed Values Added
Description The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
Title OrderConvo < 14 - Unauthenticated Arbitrary File Read
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-10-07T06:00:04.678Z

Reserved: 2025-09-09T12:51:44.415Z

Link: CVE-2025-10162

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-07T06:15:32.677

Modified: 2025-10-07T06:15:32.677

Link: CVE-2025-10162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.