PT-2025-12329 · WordPress · File Away

Sélim Lanouar

·

Published

2025-03-20

·

Updated

2025-06-27

·

CVE-2025-2539

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions File Away plugin for WordPress versions up to, and including, 3.9.9.0.1
Description The issue allows unauthorized access to data due to a missing capability check on the ajax() function. This enables unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information, by leveraging a reversible weak algorithm.
Recommendations For versions up to, and including, 3.9.9.0.1, update to a version that includes a fix for the missing capability check in the ajax() function to prevent unauthorized access. As a temporary workaround, consider disabling the ajax() function in the File Away plugin until a patch is available.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-2539

Affected Products

File Away