/Vulnerability Library

WordPress OrderConvo < 14 - Path Traversal

CVE-2025-10162
Verified

Description

WooCommerce OrderConvo WordPress plugin \u003C 14 contains a path traversal vulnerability caused by improper validation of file download paths, letting unauthenticated attackers read or download arbitrary files remotely

Severity

High

CVSS Score

7.5

Exploit Probability

4%

Published Date

May 4, 2026

Template Author

0x_akoko

CVE-2025-10162.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2025-10162
CWE ID:
cwe-22

References

https://wpscan.com/vulnerability/f878615d-955d-4365-87e0-6c928f548986/https://wordpress.org/plugins/admin-and-client-message-after-order-for-woocommerce/https://nvd.nist.gov/vuln/detail/CVE-2025-10162

Remediation Steps

Update firmware to a version later than 1.181.5 or the latest available version.