PT-2025-23895 · WordPress · Wp User Frontend Pro

Friderika Baranyai

·

Published

2025-06-05

·

Updated

2025-06-05

·

CVE-2025-3055

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP User Frontend Pro plugin for WordPress versions up to, and including, 4.1.3
Description The issue is related to insufficient file path validation in the delete avatar ajax() function, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary files on the server. This can lead to remote code execution when a critical file, such as wp-config.php, is deleted.
Recommendations For WP User Frontend Pro plugin for WordPress versions up to, and including, 4.1.3, update to a version higher than 4.1.3 to resolve the issue. As a temporary workaround, consider disabling the delete avatar ajax() function until a patch is available. Restrict access to the delete avatar ajax() function to minimize the risk of exploitation, ensuring only authorized users can perform actions that could lead to file deletion.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-3055

Affected Products

Wp User Frontend Pro