What the vulnerability does
01Description
Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4.
Explanation of Vulnerability in Simple Terms
02Summary
File Uploader for WooCommerce versions 1.0.4 and earlier contain a flaw that allows unauthenticated attackers to read sensitive data from the affected site over the network. No user interaction is required. The vulnerability does not allow attackers to modify data or disrupt service, but confidential information may be exposed.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site without authentication.
Potential impact on your site
04Site Impact
Confidential information stored on the site may be exposed to unauthenticated attackers.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated