Filtered by vendor Woosaai
Subscriptions
Total
1 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-14301 | 3 Woocommerce, Woosaai, Wordpress | 3 Woocommerce, Integration Opvius Ai For Woocommerce, Wordpress | 2026-01-14 | 9.8 Critical |
| The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.0. This is due to the `process_table_bulk_actions()` function processing user-supplied file paths without authentication checks, nonce verification, or path validation. This makes it possible for unauthenticated attackers to delete or download arbitrary files on the server via the `wsaw-log[]` POST parameter, which can be leveraged to delete critical files like `wp-config.php` or read sensitive configuration files. | ||||
Page 1 of 1.
ReportizFlow