CVE-2025-64235: WordPress Tuturn plugin < 3.6 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn allows Path Traversal.This issue affects Tuturn: from n/a before 3.6.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AmentoTech Tuturn tuturn allows Path Traversal.This issue affects Tuturn: from n/a through < 3.6.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64235?
CVE-2025-64235 is classified as a high severity vulnerability due to its potential for path traversal attacks.
How do I fix CVE-2025-64235?
To fix CVE-2025-64235, update AmentoTech Tuturn to version 3.6 or later, which addresses the path traversal issue.
What impact does CVE-2025-64235 have on my system?
CVE-2025-64235 can allow unauthorized access to restricted files and directories, potentially compromising sensitive data.
Is CVE-2025-64235 exploitable remotely?
Yes, CVE-2025-64235 is exploitable remotely, allowing attackers to manipulate file paths from outside the application.
Are there any workarounds for CVE-2025-64235?
While the primary fix is to update, temporarily restricting access to the affected application can mitigate risks associated with CVE-2025-64235.