{
 "id": "WPSEC-2026-0565",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0565/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0565/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0565/index.md",
 "title": "QA Assistants – Driven by data <= 5.3.0.0 - Unauthenticated Path Traversal to Limited File Overwrite via 'readers_name' and 'raw_name' Parameters",
 "description": "The QA Assistants – Driven by data plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.3.0.0. This is due to the public tracking endpoint building file paths from client-supplied values without validation. This makes it possible for unauthenticated attackers to overwrite existing PHP files that the web server can write to with plugin session data, which can take the site offline, and to create files outside the plugin's data directory. The written data is not executed as code.",
 "plugin": {
  "slug": "qa-heatmap-analytics",
  "name": "QA Assistants – Driven by data",
  "full_name": "QA Assistants – Driven by data",
  "wordpress_org": "https://wordpress.org/plugins/qa-heatmap-analytics/",
  "advisories_url": "https://wpsec.com/vuln/plugin/qa-heatmap-analytics/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/qa-heatmap-analytics"
 },
 "type": "TRAVERSAL",
 "cwe": [
  "CWE-22"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 9.1,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
  "severity": "Critical"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.3.0.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.3.0.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.3.0.1",
 "remediation": "Update to 5.3.0.1 or later.",
 "fix_released": "2026-10-05T09:18:13+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-07T15:30:59.596297+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0565/",
  "https://plugins.svn.wordpress.org/qa-heatmap-analytics/tags/5.3.0.1/",
  "https://wordpress.org/plugins/qa-heatmap-analytics/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/qa-heatmap-analytics",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}