CVE-2025-2578
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Mar 28, 2025
CWE ID 200
Summary
CVE-2025-2578 is a Full Path Disclosure vulnerability affecting the Amelia plugin for WordPress, specifically the 'wpAmeliaApiCall' function, in versions up to 1.2.19. Unauthenticated attackers can exploit this flaw to retrieve the full path of the web application. This vulnerability, while not damaging on its own, can aid other attacks and should be addressed promptly to secure affected websites.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.