Description
Subscriber Path Traversal in Do Lasso <= 358 versions.
Published: 2026-08-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a path traversal flaw that allows a subscriber to request files outside the intended directory tree. If exploited, an attacker could read arbitrary files on the server, potentially exposing sensitive configuration data, credentials, or user content. The weakness is classified as CWE-35, which indicates that user-supplied input is insufficiently validated before being used in file path construction.

Affected Systems

The issue affects the Do Lasso plugin for WordPress developed by Lasso Analytics, Inc., in all released versions up to and including 358. Users running this plugin on any WordPress installation are vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact, with potential confidentiality and integrity loss but no direct code execution. The EPSS metric is not available, so it is unclear how often this flaw is actively exploited, though it is not currently listed in CISA's KEV catalog. The likely attack vector involves a subscriber-level request that harnesses the path traversal logic, as implied by the description. An authenticated or unauthenticated user who can trigger the vulnerable code path may be able to fetch files from arbitrary locations, contingent upon the hosting environment's file permissions.

Generated by OpenCVE AI on August 13, 2026 at 16:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Do Lasso plugin to the latest version (>= 359) to eliminate the vulnerability.
  • If upgrading is not possible, disable or remove the Do Lasso plugin from the WordPress installation to stop the vulnerable functionality.
  • As a temporary measure, restrict file permissions and monitor subscriber endpoints for suspicious file access attempts to ensure the path traversal is not exploited.

Generated by OpenCVE AI on August 13, 2026 at 16:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Lasso Analytics, Inc.
Lasso Analytics, Inc. do Lasso
Wordpress
Wordpress wordpress
Vendors & Products Lasso Analytics, Inc.
Lasso Analytics, Inc. do Lasso
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Path Traversal in Do Lasso <= 358 versions.
Title WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
Weaknesses CWE-35
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Lasso Analytics, Inc. Do Lasso
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:23:10.611Z

Reserved: 2026-02-25T12:14:29.690Z

Link: CVE-2026-28157

cve-icon Vulnrichment

Updated: 2026-08-13T15:23:04.967Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:58.450

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:32:10Z

Weaknesses
  • CWE-35

    Path Traversal: '.../...//'