CVE-2025-2539
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 20, 2025
CWE ID 327
Summary
CVE-2025-2539 is a vulnerability affecting the File Away plugin for WordPress. The issue lies in the plugin's ajax() function, which lacks proper capability checks. As a result, unauthenticated attackers can exploit this weakness using a reversible weak algorithm, granting them unauthorized access to read the contents of arbitrary files on the affected server. These files may contain sensitive information, posing a significant security risk to WordPress sites using File Away plugin versions up to and including 3.9.9.0.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.