216.73.217.22

CVE-2018-25325

· Published 17/05/2026 13:16 · Modified 18/05/2026 17:28

Labels: CVE-2018-25325 2026-05-17CVE-2018-25325CWE-22[email protected]

Essential information

Published
17/05/2026 13:16
Modified
18/05/2026 17:28
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete sensitive files like wp-config.php outside the intended export directory.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
woocommerce / csv importer cpe:2.3:a:woocommerce:csv_importer:3.3.6:*:*:*:*:*:*:*

References