CVE-2017-17058 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 23.7% (pctl 98)
Patch early
A public exploit exists.
Description
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have "if (!defined('ABSPATH')) {exit;}" code
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 23.67% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-11-29 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| automattic | woocommerce |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal | 2017-11-28 |
References
→ the Explorer · watch your stack · NVD