First published: Mon Mar 03 2025(Updated: )
Relative Path Traversal vulnerability in NotFound Delete Comments By Status allows PHP Local File Inclusion. This issue affects Delete Comments By Status: from n/a through 2.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Delete Comments By Status | <=2.1.1 | |
WordPress Delete Comments By Status | <=1.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25130 is classified as a high severity vulnerability due to its potential for PHP Local File Inclusion.
To fix CVE-2025-25130, update the NotFound Delete Comments By Status plugin to version 2.1.2 or later.
CVE-2025-25130 affects both NotFound Delete Comments By Status versions up to 2.1.1 and WordPress Delete Comments By Status versions up to 1.5.3.
Yes, CVE-2025-25130 is exploitable remotely, allowing attackers to perform local file inclusion attacks.
CVE-2025-25130 can lead to local file inclusion, which may allow unauthorized access to sensitive files on the server.