VYPR

Wp01

by WordPress

CVEs (2)

  • CVE-2025-30567HigMar 25, 2025
    risk 0.52cvss 7.5epss 0.46

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affects WP01: from n/a through <= 2.6.2.

  • CVE-2025-2267MedMar 15, 2025
    risk 0.42cvss 6.5epss 0.00

    The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-30567 is a duplicate of this issue.