CVE-2025-69411: WordPress ionCube tester plus plugin <= 1.3 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Robert Seyfriedsberger ionCube tester plus ioncube-tester-plus allows Path Traversal.This issue affects ionCube tester plus: from n/a through <= 1.3.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely over the network without authentication or user interaction. The impact is limited to confidentiality, with high potential for information disclosure.
Which plugin versions are affected?
ionCube tester plus versions through 1.3 are affected. The available data does not identify a fixed version.
What is the likely impact of successful exploitation?
An attacker may be able to use path traversal to download files outside the intended restricted directory. This can expose sensitive files readable by the WordPress environment or server process.