plugin

Wc Carta Docente Vulnerabilities

2 known security issues reported for the Wc Carta Docente WordPress plugin. Most recent disclosed Mar 20, 2026.

2 medium

Running Wc Carta Docente on your site? Check whether your installed version is affected.

Scan your site free

ilGhera Carta Docente for WooCommerce - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter vulnerability

medium

Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter vulnerability

CVSS:
6.5
Affected:
up to 1.5.0
Fixed in:
1.5.1
Disclosed:
Mar 20, 2026

ilGhera Carta Docente for WooCommerce <= 1.5.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter

medium

The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via the 'cert' parameter of the 'wccd-delete-certificate' AJAX action. This is due to insufficient file path validation before performing a file deletion. This makes it possible for...

CVSS:
6.5
Affected:
up to 1.5.0
Fixed in:
1.5.1
Disclosed:
Mar 19, 2026

CVE-2026-2421 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database