Impact
The AR for WooCommerce WordPress plugin contains a directory traversal flaw that allows an unauthenticated actor to read any file reachable by the web‑server process. The vulnerability arises from the unchecked "file" query parameter in the plugin’s AJAX endpoints and is augmented by three broken access controls: freely minted nonces, a predictable encryption key derived from a missing licence option, and a bypassable Referer check. Because arbitrary files can be read, sensitive configuration, credential, or system files may be exposed to attackers.
Affected Systems
All installations of WebAndPrint’s AR for WooCommerce plugin for WordPress running version 8.40 or earlier are affected. No fixed release is documented in the advisory; consequently, the status of versions 8.41 and newer remains uncertain.
Risk and Exploitability
The CVSS score of 7.5 categorizes this issue as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it by sending an unauthenticated HTTP request to the plugin’s Ajax endpoint with a crafted "file" parameter that includes directory traversal sequences, thereby reading any file with permissions for the web‑server process.
OpenCVE Enrichment