First published: Tue Feb 18 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site allows Path Traversal. This issue affects Paid Videochat Turnkey Site: from n/a through 7.2.12.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Videowhisper Paid Videochat Turnkey Site | <=7.2.12 | |
WordPress Paid Videochat Turnkey Site plugin | <=7.2.12 |
Update the WordPress Paid Videochat Turnkey Site wordpress plugin to the latest available version (at least 7.3).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22663 is categorized with a severity level that indicates a significant risk due to path traversal vulnerabilities.
To fix CVE-2025-22663, update the videowhisper Paid Videochat Turnkey Site to the latest version beyond 7.2.12.
CVE-2025-22663 affects videowhisper Paid Videochat Turnkey Site up to version 7.2.12 and the WordPress Paid Videochat Turnkey Site plugin up to version 7.2.12.
CVE-2025-22663 is an improper limitation of a pathname vulnerability, commonly known as a path traversal vulnerability.
Yes, CVE-2025-22663 can potentially allow attackers to access files outside of the restricted directory, leading to data exposure.