Path Traversal Vulnerability in WooCommerce Product File Upload Plugin by add-ons.org
CVE-2026-25328

6.8MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 March 2026

What is CVE-2026-25328?

An improper limitation of pathname handling allows for path traversal vulnerabilities within the Product File Upload for WooCommerce plugin. This flaw enables attackers to access restricted directories on the server, potentially leading to unauthorized file uploads and data exposure. Specifically, versions up to and including 2.2.4 are at risk, necessitating immediate attention to prevent exploitation in your WooCommerce environment.

Affected Version(s)

Product File Upload for WooCommerce 0 <= 2.2.4

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson | Patchstack Bug Bounty Program
.