216.73.217.22

CVE-2018-25326

· Published 17/05/2026 13:16 · Modified 18/05/2026 17:05

Labels: CVE-2018-25326 2026-05-17CVE-2018-25326CWE-22[email protected]

Essential information

Published
17/05/2026 13:16
Modified
18/05/2026 17:05
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to del_fl_bkp and file_name containing traversal sequences ../../wp-config.php to access sensitive configuration files.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
google / google drive for wordpress cpe:2.3:a:google:google_drive_for_wordpress:*:*:*:*:*:wordpress:*:*

References