First published: Tue Apr 08 2025(Updated: )
The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wpe_delete_file AJAX action in all versions up to, and including, 1.8.17. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Simple WP Events | <=1.8.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2004 is considered a high severity vulnerability due to the potential for unauthenticated attackers to delete arbitrary files.
To fix CVE-2025-2004, you should update the Simple WP Events plugin to version 1.8.18 or later.
CVE-2025-2004 affects all versions of the Simple WP Events plugin for WordPress up to and including version 1.8.17.
CVE-2025-2004 is a vulnerability that allows for arbitrary file deletion due to insufficient file path validation.
Yes, CVE-2025-2004 can be exploited by unauthenticated attackers, making it particularly dangerous.