ROBERT KRUCZEK
← Back to home

CVE-2025-7518

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS v3.1: 4.9 (MEDIUM) Published: July 12, 2025 View on NVD →

Description

The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via the get_local_filename() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

Affected Products

Vendor Product Versions Affected
rsjoomla RSFirewall! * (<= 1.1.42) (affected)

CVSS Score & Vector

Base Score: 4.9 (MEDIUM)
Vector (v3.1):
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Credits / Discoverer

  • Robert Kruczek
  • Kamil Szczurowski