CVE-2025-10162: OrderConvo < 14 - Unauthenticated Arbitrary File Read
The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10162?
CVE-2025-10162 has a medium severity rating due to its potential for file disclosure through a path traversal attack.
How do I fix CVE-2025-10162?
To fix CVE-2025-10162, update the OrderConvo WordPress plugin to version 14 or later to ensure proper file path validation.
Who is affected by CVE-2025-10162?
CVE-2025-10162 affects users of the OrderConvo plugin for WooCommerce versions prior to 14.
Can CVE-2025-10162 be exploited remotely?
Yes, CVE-2025-10162 can be exploited remotely by an unauthenticated attacker to read or download arbitrary files.
What should I do if I cannot update to fix CVE-2025-10162?
If you cannot update, consider disabling the OrderConvo plugin and reviewing file access permissions to mitigate the risk of CVE-2025-10162.