PT-2025-29899 · WordPress · Madara - Core

Thái An

·

Published

2025-07-17

·

Updated

2025-07-22

·

CVE-2025-7712

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Madara - Core plugin for WordPress versions prior to 2.2.3
Description The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp manga delete zip() function. This allows unauthenticated attackers to delete arbitrary files on the server, potentially leading to remote code execution if critical files, such as wp-config.php, are deleted.
Recommendations Update the Madara - Core plugin to version 2.2.3 or later.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-7712

Affected Products

Madara - Core