216.73.217.22

CVE-2025-3520

· Published 18/04/2025 02:15 · Modified 18/04/2025 02:15

Labels: CVE-2025-3520 2025-04-18CVE-2025-3520CWE-22[email protected]

Essential information

Published
18/04/2025 02:15
Modified
18/04/2025 02:15
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CVSS metrics

Description

The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / avatar plugin cpe:2.3:a:wordpress:avatar_plugin:<0.1.4:*:*:*:*:wordpress:*:*

References