/Vulnerability Library

Yoco Payments <= 3.8.8 - Path Traversal

CVE-2025-13801
Verified

Description

Yoco Payments WordPress plugin <= 3.8.8 contains a path traversal caused by improper validation of the file parameter, letting unauthenticated attackers read arbitrary files on the server.

Severity

High

CVSS Score

7.5

Published Date

April 23, 2026

Template Author

0x_akoko

CVE-2025-13801.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE ID:
cwe-22

References

Remediation Steps

Update to the latest version beyond 3.8.8.