CVE-2025-10162
The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 3.6% (89th percentile)
- NVD status
- Deferred
- Published
- 2025-10-07
CVE-2025-10162 at NVD
5 known exploits for CVE-2025-10162
Proof-of-concept code and exploit modules indexed by Sploitus