CVE-2025-58959: WordPress Taskbot plugin <= 6.4 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Taskbot taskbot allows Path Traversal.This issue affects Taskbot: from n/a through <= 6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58959?
CVE-2025-58959 is considered a high-severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2025-58959?
To fix CVE-2025-58959, users should update AmentoTech Taskbot to version 6.5 or later.
What software does CVE-2025-58959 affect?
CVE-2025-58959 affects AmentoTech Taskbot and the WordPress Taskbot plugin, both up to and including version 6.4.
What type of vulnerability is CVE-2025-58959?
CVE-2025-58959 is an improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability.
What are the risks associated with CVE-2025-58959?
The risks associated with CVE-2025-58959 include unauthorized file access and potential file manipulation on the server.