Integration Opvius AI for WooCommerce Path Traversal Vulnerability Allowing Unauthenticated Arbitrary File Deletion or Reading

Vulnerability

A path traversal vulnerability has been identified in the Integration Opvius AI for WooCommerce plugin for WordPress, affecting all versions through 1.3.0. The vulnerability arises in the 'process_table_bulk_actions()' function, which handles user-supplied file paths without proper authentication, nonce verification, or path validation. This oversight enables unauthenticated attackers to delete or download arbitrary files from the server using the 'wsaw-log[]' POST parameter. Exploitation could lead to the deletion of critical files such as 'wp-config.php' or the unauthorized reading of sensitive configuration files.

Impact

Exploitation of this vulnerability could result in the unauthorized deletion of important files or the exposure of sensitive information from configuration files.

Reproduction

To reproduce this vulnerability, send a POST request to the WordPress site with the 'wsaw-log[]' parameter containing the path of the file to be deleted or downloaded. The 'process_table_bulk_actions()' function will process the request without authentication or validation, allowing for arbitrary file manipulation.

Added: Jan 14, 2026, 6:52 AM
Updated: Jan 14, 2026, 6:52 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.7
exploitability
8.4
remediation
0.0
relevance
2.0
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.