CVE-2025-2004
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Apr 8, 2025
CWE ID 73
Summary
CVE-2025-2004 is a vulnerability affecting the Simple WP Events plugin for WordPress. This issue stems from insufficient file path validation in the wpe_delete_file AJAX action, which exists in versions up to and including 1.8.17. As a result, unauthenticated attackers can delete arbitrary files on the server. Deletion of specific files, such as wp-config.php, can lead to remote code execution, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.