Sploitus

CVE-2025-10162

5 known exploits for CVE-2025-10162

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
3.6% (89th percentile)
NVD status
Deferred
Published
2025-10-07
CVE-2025-10162 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2025-10162

Proof-of-concept code and exploit modules indexed by Sploitus