Impact
The Linet ERP‑Woocommerce Integration plugin contains a path‑traversal weakness that allows an attacker to read or delete arbitrary files reachable by the web server process. This flaw permits file operations that can compromise the integrity or confidentiality of files on the host system.
Affected Systems
The vulnerability affects the WordPress plugin Linet ERP‑Woocommerce Integration from aribhour. Any installation using a version up to and including 3.5.12 is potentially vulnerable; versions newer than 3.5.12 are not known to contain the flaw.
Risk and Exploitability
The CVSS score is 5.9, indicating moderate severity. An EPSS score of <1% demonstrates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an external actor who can manipulate the plugin’s file‑access functionality with a crafted path value.
OpenCVE Enrichment
EUVD