CVE-2025-10162 - OrderConvo < 14 - Unauthenticated Arbitrary File Read
CVE ID : CVE-2025-10162
Published : Oct. 7, 2025, 6:15 a.m. | 27 minutes ago
Description : The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 7, 2025, 6:15 a.m. | 27 minutes ago
Description : The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...