PT-2025-27797 · WordPress · Jkdevkit

Friderika Baranyai

·

Published

2025-07-03

·

Updated

2025-07-03

·

CVE-2025-2932

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: JKDEVKIT plugin for WordPress versions up to, and including, 1.9.4
Description: The issue is related to insufficient file path validation in the font upload handler function, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary files on the server. This can lead to remote code execution if critical files, such as wp-config.php, are deleted. If WooCommerce is enabled, attackers need Contributor-level access and above to exploit this issue.
Recommendations: For versions up to, and including, 1.9.4, update to a version that fixes the insufficient file path validation in the font upload handler function to prevent arbitrary file deletion. As a temporary workaround, consider disabling the font upload handler function until a patch is available. Restrict access to the JKDEVKIT plugin to minimize the risk of exploitation, especially for users with Subscriber-level access and above, or Contributor-level access and above if WooCommerce is enabled.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-2932

Affected Products

Jkdevkit