CVE-2023-4216

CVE-2023-4216: Orders Tracking for WooCommerce < 1.2.6 - Admin+ Arbitrary File Access/Read

Vendor Unknown
Product Orders Tracking for WooCommerce
Published September 4, 2023
Last update April 23, 2025

CVSS base score

What the vulnerability does

01Description

The Orders Tracking for WooCommerce WordPress plugin before 1.2.6 doesn't validate the file_url parameter when importing a CSV file, allowing high privilege users with the manage_woocommerce capability to access any file on the web server via a Traversal attack. The content retrieved is however limited to the first line of the file.

Key dates

02Disclosure timeline

September 4, 2023 CVE published
April 23, 2025 Record updated