CVE-2026-25397 identifies a Path Traversal vulnerability ('.../...//') in Snowray Software File Uploader for WooCommerce, affecting versions up to and including 1.0.4. Rated High with a CVSS score of 7.5, this flaw could allow a remote attacker to achieve high confidentiality, integrity, and availability impacts, although it requires high attack complexity and user interaction. There is currently no evidence of active exploitation, and no public exploit code is available through Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, and its EPSS score is very low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Snowray Software | File Uploader For WooCommerce | >= 0, <= 1.0.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.