CVE-2025-3520
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 22
Summary
CVE-2025-3520 is a vulnerability affecting the Avatar plugin for WordPress. This issue arises from inadequate file path validation within a function in all versions up to 0.1.4. Authenticated attackers, including those with Subscriber-level access and above, can exploit this flaw to delete arbitrary files on the server. Deletion of specific files, such as wp-config.php, can result in remote code execution, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Avatar Plugin
Affected Vendors
- WordPress