CyberRota Analysis
AI-GeneratedThe Order Tip for WooCommerce plugin for WordPress prior to version 1.6.0 is vulnerable due to insufficient user capability checks and unrestricted file deletion paths. This flaw allows users with the Shop Manager role and higher to delete arbitrary files on the server, potentially leading to full site compromise. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this high-severity risk.
Original NVD Description
The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.