CVE-2025-47513
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CRM Forms infocob-crm-forms allows Path Traversal.This issue affects Infocob CRM Forms: from n/a through <= 2.4.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path traversal vulnerability in the Infocob CRM Forms plugin allows unauthenticated attackers to download arbitrary files from WordPress sites.
Vulnerability
Description
The Infocob CRM Forms plugin for WordPress (versions 2.4.0 and earlier) is vulnerable to a path traversal attack. The vulnerability stems from improper limitation of a pathname to a restricted directory, allowing an attacker to read files outside the intended scope. This type of flaw is commonly exploited in mass campaigns that target unpatched plugins. [1]
Exploitation
Attackers can exploit this vulnerability remotely without requiring authentication, making it easy to incorporate into automated attacks. By crafting a malicious request, they can traverse directories and download sensitive files such as wp-config.php (which contains database credentials) or backup files located elsewhere on the server. The moderately severe CVSS v3 score of 4.9 reflects the limited but real impact. [1]
Impact and
Mitigation
Successful exploitation can expose sensitive information, including login credentials and database details, potentially leading to further compromise of the WordPress site. The vendor has released version 2.4.1 to patch the flaw. Users are strongly advised to update immediately. If updating is not possible, implementing a Web Application Firewall (WAF) rule or using Patchstack's mitigation rule can block attacks until the update is applied. [1]
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.4.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.