CVE-2025-10162 affects the Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before version 14. The plugin does not properly validate the path of files requested for download, allowing a path traversal condition. An attacker can supply crafted path input to access files outside the intended directory scope and read or download arbitrary files from the underlying server. Based on the available information, this is an arbitrary file read issue caused by improper pathname restriction in a file download mechanism.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Python proof-of-concept exploit, CVE-2025-10162.py, targeting a path traversal vulnerability in the WordPress OrderConvo plugin (listed as 'Admin and Client Message After Order for WooCommerce') prior to version 14. The script uses httpx with asyncio to perform two HTTP GET requests: first, a basic liveness check against the supplied base URL, and second, a request to the vulnerable REST endpoint /wp-json/wooconvo/v1/download-file with attacker-controlled order_id and filename parameters. The exploit’s core capability is arbitrary file read, achieved by passing traversal sequences such as ../../../../wp-config.php in the filename parameter. Output is printed directly to stdout, making it suitable for quickly extracting configuration files or other readable files from the server. Repository structure is minimal: one standalone Python script with argparse-based CLI options (-u/--url and -f/--filename). No framework integration, persistence, post-exploitation automation, or payload staging is present; it is a straightforward operational PoC for unauthenticated or weakly protected file disclosure via a WordPress REST route.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.