CVE-2025-2267

The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-30567 is a duplicate of this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wp01ru:wp01:*:*:*:*:*:wordpress:*:*

History

08 Apr 2026, 18:24

Type Values Removed Values Added
Summary (en) The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information. (en) The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-30567 is a duplicate of this issue.

28 Mar 2025, 15:41

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Wp01ru wp01
Wp01ru
CPE cpe:2.3:a:wp01ru:wp01:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento WP01 para WordPress es vulnerable a la descarga arbitraria de archivos en todas las versiones hasta la 2.6.2 incluida, debido a la falta de una comprobación de capacidad y a restricciones insuficientes en la función make_archive(). Esto permite que atacantes autenticados, con acceso de suscriptor o superior, descarguen y lean el contenido de archivos arbitrarios en el servidor, que pueden contener información confidencial.
References () https://plugins.trac.wordpress.org/browser/wp01/trunk/inc/class-wp01.php#L109 - () https://plugins.trac.wordpress.org/browser/wp01/trunk/inc/class-wp01.php#L109 - Product
References () https://wordpress.org/plugins/wp01/ - () https://wordpress.org/plugins/wp01/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/900d09e8-ded5-49b9-81bf-ddfc85d3cf2b?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/900d09e8-ded5-49b9-81bf-ddfc85d3cf2b?source=cve - Third Party Advisory

15 Mar 2025, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-15 04:15

Updated : 2026-04-08 18:24


NVD link : CVE-2025-2267

Mitre link : CVE-2025-2267

CVE.ORG link : CVE-2025-2267


JSON object : View

Products Affected

wp01ru

  • wp01
CWE
CWE-862

Missing Authorization

NVD-CWE-noinfo