
A WordPress OrderConvo path traversal vulnerability (CVE-2025-10162) allows unauthenticated attackers to read wp-config.php and other sensitive files. https://www.redsecuretech.co.uk/blog/post/wordpress-orderconvo-path-traversal-reads-wp-configphp/1214 #WordPress #OrderConvo #CVE #PathTraversal #wpconfig #Unauthenticated #RESTAPI #Diamorphine #InfoSec https://t.co/ZwbIBz2bqj
Post summary
A new WordPress OrderConvo path traversal vulnerability (CVE-2025-10162) is disclosed, allowing unauthenticated attackers to read wp-config.php and other sensitive files, with a blog post link but no active exploitation or patch details.

