First published: Thu Apr 03 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in docxpresso Docxpresso allows Absolute Path Traversal. This issue affects Docxpresso: from n/a through 2.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docxpresso | >=2.6 | |
Docxpresso | <=2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-31554 is critical due to its potential for absolute path traversal, which can lead to unauthorized file access.
To fix CVE-2025-31554, update Docxpresso to a version higher than 2.6 to eliminate the path traversal vulnerability.
CVE-2025-31554 affects Docxpresso versions from n/a to 2.6.
CVE-2025-31554 is categorized as a Path Traversal vulnerability, specifically involving improper limitation of pathnames.
Yes, CVE-2025-31554 can impact WordPress sites using the Docxpresso plugin versions up to 2.6.