CVE-2025-10162 Details
Description
The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
A path traversal vulnerability has been identified in the Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin, affecting versions prior to 14. The vulnerability arises because the plugin does not properly validate file paths for downloads, potentially allowing unauthenticated attackers to read or download arbitrary files. Exploitation can be achieved by manipulating the file path to traverse directories and access sensitive files, such as the wp-config.php file.
Users are advised to update the Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin to version 14 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 7, 2025CISA-ADP
Assessed Oct 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/f878615d-955d-4365-87e0-6c928f548986/ | CISA-ADP | AdvisoryExploitRemedy |
| https://wpscan.com/vulnerability/f878615d-955d-4365-87e0-6c928f548986/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Admin and Customer Messages After Order for WooCommerce | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 7, 2025 | CVE Modified | CISA-ADP |
| Oct 7, 2025 | New CVE Received | [email protected] |
Volerion