CVE-2025-12960 | Simple CSV Table Plugin up to 1.0.1 on WordPress Shortcode csv href path traversal (EUVD-2025-203062)
A vulnerability marked as critical has been reported in Simple CSV Table Plugin up to 1.0.1 on WordPress. Affected is the function csv of the component Shortcode Handler. The manipulation of the argument href leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-12960. The attack is possible to be carried out remotely. No exploit exists.