PT-2025-44583 · WordPress · Wordpress User Extra Fields

Tonn

·

Published

2025-10-31

·

Updated

2025-10-31

·

CVE-2025-7846

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress User Extra Fields versions up to and including 16.7
Description The WordPress User Extra Fields plugin is susceptible to arbitrary file deletion. This is due to inadequate file path validation within the save fields() function. Authenticated attackers with Subscriber-level access or higher can exploit this to delete arbitrary files on the server. Deletion of critical files, such as wp-config.php, could lead to remote code execution.
Recommendations Versions up to and including 16.7 should be updated to a newer, fixed version when available. As a temporary workaround, consider restricting access to the save fields() function until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-7846

Affected Products

Wordpress User Extra Fields