Total Processing Card Payments for WooCommerce Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in the Total Processing Card Payments for WooCommerce plugin, affecting versions through 7.1.5. This vulnerability allows for improper limitation of pathname, potentially leading to arbitrary file download.

Impact

Exploitation of this vulnerability could allow a malicious actor to download any file from the affected website, including files containing login credentials or backup data.

Remediation

Users of the Total Processing Card Payments for WooCommerce plugin should update to version 7.1.6 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.