Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in the Holest Engineering Spreadsheet Price Changer plugin for WooCommerce and WP E-commerce – Light, affecting versions through 2.4.37. This vulnerability allows unauthorized users to traverse directories and access restricted files on the server.

Impact

Exploitation of this vulnerability could lead to arbitrary file download, allowing attackers to download any file from the affected website, including sensitive files such as login credentials or backup files.

Remediation

Users are advised to update to a version of the Holest Engineering Spreadsheet Price Changer plugin for WooCommerce and WP E-commerce – Light that is later than 2.4.37. For those using WordPress, Patchstack offers a virtual patch that can be applied immediately.

Added: Jun 9, 2025, 4:33 PM
Updated: Jun 9, 2025, 4:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.