CVE-2025-10162: Unknown Admin And Customer Messages After Order For Woocommerce: Orderconvo
High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.
The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
Affected products
- Unknown Admin And Customer Messages After Order For Woocommerce: Orderconvo: before 14 (fixed in 14)
Published 2025-10-07. Last modified 2026-10-09.