CVE-2025-10134: Goza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Deletion
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the aloneimportpackrestoredata() function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10134?
CVE-2025-10134 has a high severity rating due to the potential for arbitrary file deletion by unauthenticated users.
How do I fix CVE-2025-10134?
To fix CVE-2025-10134, update the Goza Nonprofit Charity WordPress Theme to version 3.2.3 or later.
Who is affected by CVE-2025-10134?
CVE-2025-10134 affects all versions of the Goza Nonprofit Charity WordPress Theme up to and including version 3.2.2.
What impact does CVE-2025-10134 have on my website?
The vulnerability allows attackers to delete files on your server, which can lead to loss of data and potential site downtime.
Is authentication required to exploit CVE-2025-10134?
No, exploitation of CVE-2025-10134 does not require authentication, making it particularly dangerous.