
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68862 is a Path Traversal vulnerability (CWE-22) in the Woo File Dropzone WordPress plugin by Murtaza Bhurgri that enables authenticated attackers to perform arbitrary file deletion. It affects all versions up to and including 1.1.7, with no official patch available as of the disclosure date. The vulnerability was reported by security researcher Skalucy on November 23, 2025, and published by Patchstack on February 5, 2026. It carries a CVSS v3.1 base score of 7.7 (High) (Patchstack).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and stems from insufficient validation of file path inputs within the Woo File Dropzone plugin. An attacker can supply crafted path sequences (e.g., ../ traversal sequences) to escape the intended directory boundary and reference arbitrary files on the server. Exploitation requires only Subscriber-level authentication (low privileges), no user interaction, and operates over the network with low attack complexity. The changed scope in the CVSS vector indicates the impact extends beyond the plugin's own security context to the broader WordPress installation (Patchstack).
Successful exploitation allows an authenticated attacker with Subscriber-level access to delete arbitrary files on the web server, including WordPress core files, configuration files (e.g., wp-config.php), or other critical assets. Deletion of core files can render the website completely non-functional, resulting in a high availability impact. While the CVSS vector indicates no direct confidentiality or integrity impact, the ability to delete wp-config.php or similar files could indirectly facilitate further attacks such as site takeover or database credential exposure (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.021%, indicating a currently low probability of exploitation in the wild. However, Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity. There is no current CISA KEV catalog listing for this CVE (Patchstack).
wp-content/plugins/woo-file-dropzone/readme.txt.../../wp-config.php or ../../wp-includes/functions.php) in the file path parameter to reference files outside the intended upload directory.wp-config.php can force a WordPress reinstallation prompt, potentially allowing site takeover; deletion of core files causes site outage (Patchstack).../ or URL-encoded traversal sequences (e.g., %2e%2e%2f, %2e%2e/) in file path parameters.wp-config.php, core files in wp-includes/, or wp-admin/ directories; missing plugin or theme files not explained by legitimate administrative actions.wp-content/uploads/ directory, which may indicate attempted but failed traversal.No official patch from the plugin developer is available as of the disclosure date; the vulnerable version remains ≤ 1.1.7. Site administrators should immediately deactivate and remove the Woo File Dropzone plugin until a patched version is released. Patchstack has issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts in the interim. Additionally, restricting Subscriber-level user registration on the WordPress site reduces the attack surface by limiting who can reach the vulnerable functionality (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher Skalucy, classifies it as high priority and warns it is the type of vulnerability commonly leveraged in mass-exploit campaigns against WordPress sites. No additional notable vendor statements, researcher commentary, or significant media coverage beyond the Patchstack advisory have been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."