Impact
The AR for WooCommerce WordPress plugin contains a directory traversal flaw that allows an unauthenticated attacker to read the contents of any file accessible to the web‑server process using the unvalidated "file" query parameter. The vulnerability is enabled by three broken access controls: nonces that can be created without authentication, a predictable encryption key derived from a missing licence option, and a Referer check that can be easily bypassed with attacker‑controlled headers.
Affected Systems
All installations of WebAndPrint’s AR for WooCommerce plugin for WordPress running version 8.40 or earlier are affected. No patched release is documented in the advisory; therefore, the status of versions 8.41 and newer remains uncertain.
Risk and Exploitability
The CVSS score of 7.5 categorizes this issue as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it by sending an unauthenticated HTTP request to the plugin’s Ajax endpoint with a crafted "file" parameter that includes directory traversal sequences, thereby reading any file with permissions for the web‑server process.
OpenCVE Enrichment