VYPR
Medium severity4.9NVD Advisory· Published May 23, 2025· Updated Apr 23, 2026

CVE-2025-47513

CVE-2025-47513

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CRM Forms infocob-crm-forms allows Path Traversal.This issue affects Infocob CRM Forms: from n/a through <= 2.4.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path traversal vulnerability in the Infocob CRM Forms plugin allows unauthenticated attackers to download arbitrary files from WordPress sites.

Vulnerability

Description

The Infocob CRM Forms plugin for WordPress (versions 2.4.0 and earlier) is vulnerable to a path traversal attack. The vulnerability stems from improper limitation of a pathname to a restricted directory, allowing an attacker to read files outside the intended scope. This type of flaw is commonly exploited in mass campaigns that target unpatched plugins. [1]

Exploitation

Attackers can exploit this vulnerability remotely without requiring authentication, making it easy to incorporate into automated attacks. By crafting a malicious request, they can traverse directories and download sensitive files such as wp-config.php (which contains database credentials) or backup files located elsewhere on the server. The moderately severe CVSS v3 score of 4.9 reflects the limited but real impact. [1]

Impact and

Mitigation

Successful exploitation can expose sensitive information, including login credentials and database details, potentially leading to further compromise of the WordPress site. The vendor has released version 2.4.1 to patch the flaw. Users are strongly advised to update immediately. If updating is not possible, implementing a Web Application Firewall (WAF) rule or using Patchstack's mitigation rule can block attacks until the update is applied. [1]

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.