CVE-2025-59566: WordPress Workreap (theme's plugin) plugin <= 3.3.5 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Workreap (theme's plugin) workreap allows Path Traversal.This issue affects Workreap (theme's plugin): from n/a through <= 3.3.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59566?
CVE-2025-59566 has a high severity due to its potential for unauthorized file access and arbitrary code execution.
How do I fix CVE-2025-59566?
To fix CVE-2025-59566, update the AmentoTech Workreap plugin to version 3.3.6 or later.
What specific feature is affected by CVE-2025-59566?
CVE-2025-59566 affects the improper limitation of a pathname, allowing for path traversal vulnerabilities.
Which versions of Workreap are vulnerable to CVE-2025-59566?
Workreap versions from n/a up to and including 3.3.5 are vulnerable to CVE-2025-59566.
Who is affected by CVE-2025-59566?
Users of the AmentoTech Workreap theme plugin, particularly those using version 3.3.5 or earlier, are affected by CVE-2025-59566.