
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69325 is a Path Traversal vulnerability (CWE-35: Path Traversal: '.../...//') affecting the Primer MyData for WooCommerce WordPress plugin by primersoftware. It affects all versions up to and including 4.2.8, with version 4.2.9 containing the fix. The vulnerability was reported on November 24, 2025, and published on February 20, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (Patchstack, Feedly).
The vulnerability is classified under CWE-35 (Path Traversal: '.../...//'), a variant of path traversal where specially crafted sequences such as .../...// are used to bypass input sanitization and traverse directory structures on the server. The flaw is exploitable remotely over the network with no authentication required, no user interaction, and low attack complexity, making it accessible to unauthenticated attackers. The specific code path within the plugin that fails to properly sanitize file path inputs allows an attacker to read files outside the intended directory scope (Patchstack).
Successful exploitation results in unauthorized read access to files on the server, posing a confidentiality risk. There is no integrity or availability impact based on the CVSS assessment. An attacker could potentially read sensitive WordPress configuration files (e.g., wp-config.php) or other server-side files accessible to the web server process, which could expose database credentials or other secrets and facilitate further compromise (Patchstack).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.021% (0.000210), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
.../...// or variations thereof to escape the intended directory.../../../../wp-config.php)..../...//, ....//, or URL-encoded equivalents (e.g., %2e%2e%2f) in file path parameters.primer-mydata plugin path; HTTP 200 responses to requests referencing wp-config.php or other sensitive files.wp-config.php or other sensitive files in server access logs.Update the Primer MyData for WooCommerce plugin to version 4.2.9 or later, which contains the patch for this vulnerability. If an immediate update is not possible, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. Site administrators should also consider restricting direct file access to sensitive directories via server configuration (e.g., .htaccess rules) as a defense-in-depth measure (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."