CVE-2026-25397 | Snowray File Uploader for WooCommerce Plugin up to 1.0.4 on WordPress path traversal
A vulnerability has been found in Snowray File Uploader for WooCommerce Plugin up to 1.0.4 on WordPress and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to path traversal: '.../...//'.
This vulnerability is documented as CVE-2026-25397. The attack can be initiated remotely. There is not any exploit available.