๐Ÿ” CVE Alert

CVE-2026-25397

HIGH 7.5

WordPress File Uploader for WooCommerce plugin <= 1.0.4 - Path Traversal vulnerability

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
7th

Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4.

CWE CWE-35
Vendor snowray software
Product file uploader for woocommerce
Published Mar 25, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for snowray software file uploader for woocommerce

Be the first to know when new high vulnerabilities affecting snowray software file uploader for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Snowray Software / File Uploader for WooCommerce
n/a โ‰ค <= 1.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/file-uploader-for-woocommerce/vulnerability/wordpress-file-uploader-for-woocommerce-plugin-1-0-4-path-traversal-vulnerability?_s_id=cve

Credits

johska | Patchstack Bug Bounty Program