
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68002 is a Path Traversal (Arbitrary File Download) vulnerability in the Open User Map WordPress plugin by 100plugins, affecting all versions up to and including 1.4.16. The flaw allows authenticated attackers with at least Subscriber-level privileges to download arbitrary files from the affected WordPress installation. It was reported on November 30, 2025, by researcher Phat RiO and published on February 16–20, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack, Wordfence).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The plugin fails to properly sanitize or restrict user-supplied file path input, allowing an authenticated attacker to craft a request that traverses outside the intended directory and retrieves arbitrary files from the server's filesystem. Exploitation requires a low-privilege authenticated account (e.g., Subscriber role) and no user interaction, making it straightforward to abuse in shared or open-registration WordPress environments. The attack vector is network-based with low complexity (Patchstack).
Successful exploitation allows an attacker to download arbitrary files from the WordPress server, including sensitive configuration files such as wp-config.php (which contains database credentials), backup archives, private keys, or other sensitive data stored on the filesystem. This can lead to full credential compromise, enabling database access, account takeover, and potential lateral movement within the hosting environment. Confidentiality is fully impacted while integrity and availability are not directly affected by this vulnerability (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
https://target.com/wp-content/plugins/open-user-map/readme.txt.../../wp-config.php) to reference files outside the plugin's intended directory.wp-config.php for database credentials, .env files, or backup archives).wp-config.php) to access the database directly or escalate privileges within the WordPress installation (Patchstack).../, ..%2F, or ..%5C in file path parameters; unusual requests for files like wp-config.php, .env, or backup archives originating from low-privilege user sessions.%2e%2e%2f) and HTTP 200 responses for non-standard file types; repeated requests from the same authenticated user to different file paths.The vulnerability is patched in Open User Map version 1.4.17; administrators should update immediately via the WordPress plugin dashboard or manually. Patchstack has issued a virtual patching (mitigation) rule for its users to block exploitation attempts until the plugin is updated. If updating is not immediately possible, consider disabling the plugin or restricting site registration to prevent attackers from obtaining the required Subscriber-level access (Patchstack).
Wordfence included CVE-2025-68002 in its weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as part of broader plugin security coverage (Wordfence). Patchstack, which coordinated the disclosure through its Active VDP program, classified the vulnerability as high priority and emphasized the risk of mass-exploit campaigns targeting WordPress plugins with this class of vulnerability (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."