VYPR

OrderConvo

by WordPress

CVEs (5)

  • CVE-2024-33566CriApr 29, 2024
    risk 0.65cvss 10.0epss 0.01

    Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.

  • CVE-2025-10162HigOct 7, 2025
    risk 0.52cvss 7.5epss 0.04

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

  • CVE-2024-13355MedJan 16, 2025
    risk 0.35cvss 5.4epss 0.00

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for…

  • CVE-2025-13389MedNov 25, 2025
    risk 0.27cvss 5.3epss 0.00

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for…

  • CVE-2025-13452MedNov 25, 2025
    risk 0.21cvss 4.3epss 0.00

    The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no…