CVE-2025-8422: Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.7.6.7 via the sendemail() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8422?
CVE-2025-8422 is classified as a high severity vulnerability due to the potential for unauthenticated attackers to read arbitrary files.
How do I fix CVE-2025-8422?
To fix CVE-2025-8422, update the Propovoice All-in-One Client Management System plugin to version 1.7.6.8 or later.
Who is affected by CVE-2025-8422?
Any user of the Propovoice All-in-One Client Management System plugin for WordPress versions up to and including 1.7.6.7 is affected by CVE-2025-8422.
What functionality is vulnerable in CVE-2025-8422?
The vulnerability in CVE-2025-8422 exists within the send_email() function, allowing for arbitrary file reads.
Can CVE-2025-8422 be exploited remotely?
Yes, CVE-2025-8422 can be exploited remotely by unauthenticated attackers.