VYPR

Direct Download For Woocommerce

by WordPress

CVEs (1)

  • CVE-2026-15019HigSep 10, 2026
    risk 0.49cvss 7.5epss

    The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the…