CVE-2025-31635: WordPress CLEVER plugin <= 2.6.2 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup CLEVER allows Path Traversal. This issue affects CLEVER: from n/a through 2.6.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup CLEVER lbg-audio11-html5-shoutcasthistory allows Path Traversal.This issue affects CLEVER: from n/a through <= 2.6.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31635?
CVE-2025-31635 is considered a high severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2025-31635?
To fix CVE-2025-31635, update the CLEVER software to version 2.7 or later, as earlier versions are affected.
What software is affected by CVE-2025-31635?
CVE-2025-31635 affects LambertGroup CLEVER versions from n/a through 2.6.
What type of vulnerability is CVE-2025-31635?
CVE-2025-31635 is an improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability.
Can CVE-2025-31635 lead to data exposure?
Yes, CVE-2025-31635 can potentially lead to unauthorized access and data exposure through path traversal.