CVE-2025-10162: Unknown Admin And Customer Messages After Order For Woocommerce: Orderconvo

High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.

The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

Affected products

  • Unknown Admin And Customer Messages After Order For Woocommerce: Orderconvo: before 14 (fixed in 14)

Published 2025-10-07. Last modified 2026-10-09.