CVE-2025-68002
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68002 is a Path Traversal (Arbitrary File Download) vulnerability in the Open User Map WordPress plugin by 100plugins, affecting all versions up to and including 1.4.16. The flaw allows authenticated attackers with at least Subscriber-level privileges to download arbitrary files from the affected WordPress installation. It was reported on November 30, 2025, by researcher Phat RiO and published on February 16–20, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Wordfence).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The plugin fails to properly sanitize or restrict user-supplied file path input, allowing an authenticated attacker to craft a request that traverses outside the intended directory and retrieves arbitrary files from the server's filesystem. Exploitation requires a low-privilege authenticated account (e.g., Subscriber role) and no user interaction, making it straightforward to abuse in shared or open-registration WordPress environments. The attack vector is network-based with low complexity (Patchstack).

Impact

Successful exploitation allows an attacker to download arbitrary files from the WordPress server, including sensitive configuration files such as wp-config.php (which contains database credentials), backup archives, private keys, or other sensitive data stored on the filesystem. This can lead to full credential compromise, enabling database access, account takeover, and potential lateral movement within the hosting environment. Confidentiality is fully impacted while integrity and availability are not directly affected by this vulnerability (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Open User Map plugin (version ≤ 1.4.16) using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at https://target.com/wp-content/plugins/open-user-map/readme.txt.
  2. Obtain low-privilege credentials: Register or obtain a Subscriber-level (or higher) account on the target WordPress site, which may be possible if user registration is open.
  3. Authenticate: Log in to the WordPress site to obtain a valid session cookie or nonce.
  4. Craft path traversal request: Send an authenticated HTTP request to the vulnerable plugin endpoint with a manipulated file path parameter using directory traversal sequences (e.g., ../../wp-config.php) to reference files outside the plugin's intended directory.
  5. Retrieve sensitive files: Download the response containing the contents of the targeted file (e.g., wp-config.php for database credentials, .env files, or backup archives).
  6. Escalate access: Use harvested credentials (e.g., database username/password from wp-config.php) to access the database directly or escalate privileges within the WordPress installation (Patchstack).

Indicators of compromise

  • Network: Authenticated HTTP GET/POST requests to Open User Map plugin endpoints containing path traversal sequences such as ../, ..%2F, or ..%5C in file path parameters; unusual requests for files like wp-config.php, .env, or backup archives originating from low-privilege user sessions.
  • Logs: WordPress or web server access logs showing requests to plugin-related URLs with encoded traversal patterns (e.g., %2e%2e%2f) and HTTP 200 responses for non-standard file types; repeated requests from the same authenticated user to different file paths.
  • File System: No direct file system artifacts are expected from read-only file download exploitation, but evidence of subsequent access using harvested credentials (e.g., new admin accounts, unexpected database queries) may indicate post-exploitation activity.

Mitigation and workarounds

The vulnerability is patched in Open User Map version 1.4.17; administrators should update immediately via the WordPress plugin dashboard or manually. Patchstack has issued a virtual patching (mitigation) rule for its users to block exploitation attempts until the plugin is updated. If updating is not immediately possible, consider disabling the plugin or restricting site registration to prevent attackers from obtaining the required Subscriber-level access (Patchstack).

Community reactions

Wordfence included CVE-2025-68002 in its weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as part of broader plugin security coverage (Wordfence). Patchstack, which coordinated the disclosure through its Active VDP program, classified the vulnerability as high priority and emphasized the risk of mass-exploit campaigns targeting WordPress plugins with this class of vulnerability (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6128NONEN/A
  • all-in-one-wp-migration-unlimited-extension
NoYesAug 28, 2026
CVE-2026-5510NONEN/A
  • give
NoYesAug 28, 2026
CVE-2026-79996NONEN/A
  • user-registration
NoYesAug 28, 2026
CVE-2026-79995NONEN/A
  • user-registration
NoYesAug 28, 2026
CVE-2026-79706NONEN/A
  • breeze
NoYesAug 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management