QA Assistants – Driven by data <= 5.3.0.0 - Unauthenticated Path Traversal to Limited File Overwrite via 'readers_name' and 'raw_name' Parameters

Critical 9.1 CWE-22Fixed in 5.3.0.1
ID
WPSEC-2026-0565
Plugin
QA Assistants – Driven by data (qa-heatmap-analytics)
Affected
all versions before 5.3.0.1
Remediation
Update to 5.3.0.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness
CWE-22
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
QA Assistants – Driven by data on WPSec AttackSurface
Fix released
Published

Description

The QA Assistants – Driven by data plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.3.0.0. This is due to the public tracking endpoint building file paths from client-supplied values without validation. This makes it possible for unauthenticated attackers to overwrite existing PHP files that the web server can write to with plugin session data, which can take the site offline, and to create files outside the plugin's data directory. The written data is not executed as code.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0