PT-2025-30004 · WordPress · Attachment Manager

Johannes Skamletz

+1

·

Published

2025-07-18

·

Updated

2025-07-18

·

CVE-2025-7643

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Attachment Manager plugin for WordPress versions up to and including 2.1.2
Description The Attachment Manager plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation within the handle actions() function. This allows unauthenticated attackers to delete arbitrary files on the server, potentially leading to remote code execution if critical files, such as wp-config.php, are deleted.
Recommendations Update the Attachment Manager plugin to a version later than 2.1.2.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-7643

Affected Products

Attachment Manager