CVE-2023-4216: Villatheme Orders Tracking For Woocommerce
Low severity, CVSS 2.7. EPSS: 0.7% chance of exploitation in the next 30 days.
The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.
Affected products
- Villatheme Orders Tracking For Woocommerce: before 1.2.6 (fixed in 1.2.6)
Published 2023-09-04. Last modified 2026-06-17.