CVE-2025-2539

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 327

Summary

CVE-2025-2539 is a vulnerability affecting the File Away plugin for WordPress. The issue lies in the plugin's ajax() function, which lacks proper capability checks. As a result, unauthenticated attackers can exploit this weakness using a reversible weak algorithm, granting them unauthorized access to read the contents of arbitrary files on the affected server. These files may contain sensitive information, posing a significant security risk to WordPress sites using File Away plugin versions up to and including 3.9.9.0.1.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share