CVE-2025-48267: WordPress WP Pipes plugin <= 1.4.2 - Arbitrary File Deletion Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue affects WP Pipes: from n/a through 1.4.2.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes wp-pipes allows Path Traversal.This issue affects WP Pipes: from n/a through <= 1.4.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48267?
CVE-2025-48267 has been classified as a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2025-48267?
To fix CVE-2025-48267, update ThimPress WP Pipes to version 1.4.3 or later.
What kind of vulnerability is CVE-2025-48267?
CVE-2025-48267 is classified as a Path Traversal vulnerability, allowing attackers to access files outside of the intended directory.
Which versions of ThimPress WP Pipes are affected by CVE-2025-48267?
CVE-2025-48267 affects ThimPress WP Pipes from version n/a up to and including 1.4.2.
Can CVE-2025-48267 affect WordPress installations?
Yes, CVE-2025-48267 affects the WordPress WP Pipes plugin from version n/a through 1.4.2.