Yoco Payments <= 3.8.8 - Path Traversal
CVE-2025-13801
Verified
Description
Yoco Payments WordPress plugin <= 3.8.8 contains a path traversal caused by improper validation of the file parameter, letting unauthenticated attackers read arbitrary files on the server.
Severity
High
CVSS Score
7.5
Published Date
April 23, 2026
Template Author
0x_akoko
CVE-2025-13801.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE ID:
cwe-22
References
Remediation Steps
Update to the latest version beyond 3.8.8.