# CVE-2025-13339: Hippoo Mobile App For WooCommerce - Path Traversal

> Live exploitation tracking for CVE-2025-13339 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2025-13339

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 7.5
- **Public exploit available:** Yes
- **Affected products:** Hippooo Hippoo Mobile App For WooCommerce
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** wordpress, cms, ecommerce

## Description

The Hippoo Mobile App For WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

## CrowdSec analysis

[CVE-2025-13339](https://euvd.enisa.europa.eu/vulnerability/CVE-2025-13339) is a path traversal vulnerability in the Hippoo Mobile App For WooCommerce plugin for WordPress, affecting all versions up to and including 1.7.1. This flaw allows unauthenticated attackers to read arbitrary files on the server via the template_redirect() function, potentially exposing sensitive information such as configuration files, credentials, or user data.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2025-13339 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
CrowdSec data also reveals a clear uptick in attacks involving CVE-2025-13339 over the past week. Activity is above the usual baseline, suggesting growing attention from attackers. This may reflect rising awareness, recent exploit releases, or expanded targeting efforts.

Attackers exploit this vulnerability by sending requests with the `hippoo_serve` query parameter containing directory traversal sequences (e.g., `../`) to WordPress endpoints, such as `/?hippoo_serve=../../../../wp-config.php`, in order to read arbitrary files from the server.

## Timeline

- 2025-12-10: CVE Published. CVE-2025-13339 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2025-13339 exploitation attempts against the CrowdSec Network.
- 2026-08-19: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2025-13339 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-13339.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2025-13339) follows observed exploitation activity for CVE-2025-13339. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
