First published: Thu Apr 17 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rockgod100 Theme File Duplicator allows Path Traversal. This issue affects Theme File Duplicator: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Theme File Duplicator Plugin | <=1.3 | |
rockgod100 Theme File Duplicator | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27283 is classified as a medium severity vulnerability due to its potential for exploitation via path traversal.
CVE-2025-27283 allows unauthorized file access, potentially exposing sensitive files on the server.
To mitigate CVE-2025-27283, it is recommended to update the Theme File Duplicator to the latest version that addresses this vulnerability.
CVE-2025-27283 affects Theme File Duplicator versions up to and including 1.3.
As of now, there are no publicly known exploits for CVE-2025-27283, but it is advisable to take precautionary measures.