CVE-2025-62992
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-62992 is a Cross-Site Request Forgery (CSRF) vulnerability in the Everest Backup plugin for WordPress that enables path traversal attacks, allowing unauthorized access to read and potentially modify sensitive files on affected systems. It affects Everest Backup versions up to and including 2.3.11 (with CPE analysis initially scoped to 2.3.9). The vulnerability was reported by researcher 0xd4rk5id3 on October 23, 2025, and publicly disclosed by Patchstack on December 31, 2025. NVD assigns a CVSS v3.1 base score of 8.1 (High), while Patchstack's CNA scores it at 6.5 (Medium) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-352 (Cross-Site Request Forgery), where the Everest Backup plugin fails to properly validate the origin of requests, allowing an attacker to forge requests on behalf of an authenticated user. This CSRF weakness is chained with a path traversal flaw, enabling the forged request to access files outside the intended directory scope on the WordPress server. Exploitation requires the attacker to trick an authenticated (privileged) WordPress user into clicking a malicious link or visiting a crafted page, at which point the forged request is executed under the victim's session. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to read sensitive files on the server (high confidentiality impact) and potentially modify backup files or other accessible data (high integrity impact per NVD scoring), without any availability impact. The attack targets WordPress sites running the vulnerable plugin and could expose backup archives containing database credentials, configuration files, or other sensitive site data. Because the attack is mediated through a privileged user's session, the scope of accessible files may extend to anything the web server process can read (Patchstack, Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.015% (0.000150), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority, noting it is unlikely to be exploited despite the theoretical potential for mass-exploit campaigns targeting WordPress plugins (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Everest Backup plugin at versions 2.3.11 or earlier using tools like WPScan or passive enumeration of plugin directories (e.g., /wp-content/plugins/everest-backup/).
  2. Craft malicious request: Construct a forged HTTP request targeting the vulnerable Everest Backup endpoint that includes a path traversal payload (e.g., ../../wp-config.php) in a parameter that is not properly validated.
  3. Deliver CSRF payload: Embed the forged request in a malicious webpage, email link, or crafted form that, when visited or submitted by an authenticated WordPress administrator, automatically triggers the request in the context of the victim's session.
  4. Trigger exploitation: Lure the authenticated administrator to interact with the malicious content (e.g., via phishing), causing the CSRF request to execute and the path traversal to access or exfiltrate sensitive files.
  5. Retrieve sensitive data: Depending on the traversal path, the attacker may gain access to wp-config.php (containing database credentials), backup archives, or other sensitive server files accessible to the web process (Patchstack).

Indicators of compromise

  • Network: Unexpected HTTP requests to Everest Backup plugin endpoints originating from unusual referrers or cross-origin sources; outbound connections from the web server to unknown external IPs following plugin interactions.
  • Logs: WordPress or web server access logs showing requests to Everest Backup plugin URLs with path traversal sequences (e.g., ../, %2e%2e%2f) in parameters; requests lacking valid nonce values in plugin-related actions.
  • File System: Unexpected access timestamps on sensitive files such as wp-config.php, backup archives, or files outside the WordPress root; new or modified backup files in unexpected locations.
  • Process: Web server processes reading files outside the WordPress installation directory, particularly configuration or credential files.

Mitigation and workarounds

The vulnerability is patched in Everest Backup version 2.3.12; all users should update immediately (Patchstack). If an immediate update is not possible, site administrators should disable the Everest Backup plugin until patching is feasible, and restrict access to backup functionality to trusted administrators only. Additional mitigations include implementing same-site cookie attributes, enforcing strict CSRF token validation at the server level, and monitoring for suspicious file access patterns. Patchstack users can enable auto-update for vulnerable plugins to receive protection automatically.

Community reactions

Patchstack, which discovered and disclosed the vulnerability, classifies it as low priority with no impactful threat, noting it is unlikely to be exploited despite the theoretical risk (Patchstack). The vulnerability received routine coverage from automated vulnerability tracking services and was noted on social platforms such as Bluesky and CIRCL's vulnerability lookup service, but no significant researcher commentary or media coverage has been identified beyond standard disclosure channels.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management