PT-2025-37289 · WordPress · Lws Cleaner

Jonas Benjamin Friedli

·

Published

2025-09-12

·

Updated

2025-09-17

·

CVE-2025-8575

CVSS v3.1
7.2
VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LWS Cleaner plugin for WordPress versions up to and including 2.4.1.3
Description: The LWS Cleaner plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation within the
lws cl delete file
function. This allows authenticated attackers with Administrator-level access or higher to delete arbitrary files on the server. Deletion of specific files, such as
wp-config.php
, could lead to remote code execution.
Recommendations: Update the LWS Cleaner plugin to a version newer than 2.4.1.3.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-8575

Affected Products

Lws Cleaner