Executive brief
The Woocommerce Book Price plugin for WordPress is vulnerable to a security flaw that allows unauthorized users to download sensitive files from the web server. This plugin is typically used to manage pricing for book-related products on e-commerce sites. An attacker could exploit this to steal configuration files containing database credentials or other private site data, potentially leading to a full site takeover.
Technical details
A path traversal vulnerability (CWE-22) exists in the Woocommerce Book Price plugin for WordPress in versions up to and including 1.3. The flaw allows an attacker to bypass directory restrictions and download arbitrary files from the server. While the advisory title mentions 'Subscriber' privileges, the CVSS vector (PR:N) suggests the vulnerability may be exploitable without authentication. An attacker can leverage this to retrieve sensitive system files, such as wp-config.php, which contains database credentials. As of the advisory date, no official patch has been released.
Affected products
- WPos Woocommerce Book Price <= 1.3
Timeline
- 2025-09-30: other: Vulnerability reported by researcher 0xd4rk5id3
- 2026-01-15: advisory: Patchstack published the vulnerability details
- 2026-06-17: disclosed: CVE published to NVD