Medium severity5.9NVD Advisory· Published May 3, 2025· Updated Apr 15, 2026
CVE-2025-4222
CVE-2025-4222
Description
The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in a publicly accessible location. This makes it possible for unauthenticated attackers to extract sensitive data from database backup files. An index file is present, so a brute force attack would need to be successful in order to compromise any data.
Affected products
1- Range: <=1.8.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/database-toolset/trunk/admin/class-database-toolset-admin.phpnvd
- plugins.trac.wordpress.org/browser/database-toolset/trunk/admin/class-database-toolset-backup.phpnvd
- www.guyshavit.com/post/cve-2025-4222nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/fa452a9a-9e26-41a1-8dea-4bafaf735beenvd
News mentions
0No linked articles in our index yet.