Total Processing Card Payments for WooCommerce Path Traversal Vulnerability
Vulnerability
A path traversal vulnerability has been identified in the Total Processing Card Payments for WooCommerce plugin, affecting versions through 7.1.5. This vulnerability allows for improper limitation of pathname, potentially leading to arbitrary file download.
Impact
Exploitation of this vulnerability could allow a malicious actor to download any file from the affected website, including files containing login credentials or backup data.
Remediation
Users of the Total Processing Card Payments for WooCommerce plugin should update to version 7.1.6 or later. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
