CVE-2025-68862: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68862 is a Path Traversal vulnerability (CWE-22) in the Woo File Dropzone WordPress plugin by Murtaza Bhurgri that enables authenticated attackers to perform arbitrary file deletion. It affects all versions up to and including 1.1.7, with no official patch available as of the disclosure date. The vulnerability was reported by security researcher Skalucy on November 23, 2025, and published by Patchstack on February 5, 2026. It carries a CVSS v3.1 base score of 7.7 (High) (Patchstack).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and stems from insufficient validation of file path inputs within the Woo File Dropzone plugin. An attacker can supply crafted path sequences (e.g., ../ traversal sequences) to escape the intended directory boundary and reference arbitrary files on the server. Exploitation requires only Subscriber-level authentication (low privileges), no user interaction, and operates over the network with low attack complexity. The changed scope in the CVSS vector indicates the impact extends beyond the plugin's own security context to the broader WordPress installation (Patchstack).

Impact

Successful exploitation allows an authenticated attacker with Subscriber-level access to delete arbitrary files on the web server, including WordPress core files, configuration files (e.g., wp-config.php), or other critical assets. Deletion of core files can render the website completely non-functional, resulting in a high availability impact. While the CVSS vector indicates no direct confidentiality or integrity impact, the ability to delete wp-config.php or similar files could indirectly facilitate further attacks such as site takeover or database credential exposure (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the wild. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity. There is no current CISA KEV catalog listing for this CVE (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Woo File Dropzone plugin version ≤ 1.1.7 using tools like WPScan, Shodan, or by checking the plugin's readme.txt file at wp-content/plugins/woo-file-dropzone/readme.txt.
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site, which is often possible on e-commerce sites using WooCommerce.
  3. Identify vulnerable endpoint: Locate the plugin's file handling functionality, likely a form submission or AJAX endpoint that accepts a filename or path parameter for file operations.
  4. Craft path traversal payload: Construct a request with a path traversal sequence (e.g., ../../wp-config.php or ../../wp-includes/functions.php) in the file path parameter to reference files outside the intended upload directory.
  5. Trigger file deletion: Submit the crafted request to the vulnerable endpoint, causing the server to delete the targeted file outside the plugin's restricted directory.
  6. Achieve objective: Deletion of wp-config.php can force a WordPress reinstallation prompt, potentially allowing site takeover; deletion of core files causes site outage (Patchstack).

Indicators of compromise

  • Logs: WordPress or web server access logs showing authenticated POST or AJAX requests to Woo File Dropzone plugin endpoints containing ../ or URL-encoded traversal sequences (e.g., %2e%2e%2f, %2e%2e/) in file path parameters.
  • File System: Unexpected absence of critical WordPress files such as wp-config.php, core files in wp-includes/, or wp-admin/ directories; missing plugin or theme files not explained by legitimate administrative actions.
  • Logs: PHP error logs showing file deletion failures or permission errors for paths outside the wp-content/uploads/ directory, which may indicate attempted but failed traversal.
  • File System: Timestamps on remaining files showing recent unexpected modification or access times correlating with suspicious log entries (Patchstack).

Mitigation and workarounds

No official patch from the plugin developer is available as of the disclosure date; the vulnerable version remains ≤ 1.1.7. Site administrators should immediately deactivate and remove the Woo File Dropzone plugin until a patched version is released. Patchstack has issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts in the interim. Additionally, restricting Subscriber-level user registration on the WordPress site reduces the attack surface by limiting who can reach the vulnerable functionality (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through researcher Skalucy, classifies it as high priority and warns it is the type of vulnerability commonly leveraged in mass-exploit campaigns against WordPress sites. No additional notable vendor statements, researcher commentary, or significant media coverage beyond the Patchstack advisory have been identified at this time (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management