CVE-2025-69325: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-69325 is a Path Traversal vulnerability (CWE-35: Path Traversal: '.../...//') affecting the Primer MyData for WooCommerce WordPress plugin by primersoftware. It affects all versions up to and including 4.2.8, with version 4.2.9 containing the fix. The vulnerability was reported on November 24, 2025, and published on February 20, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (Patchstack, Feedly).

Technical details

The vulnerability is classified under CWE-35 (Path Traversal: '.../...//'), a variant of path traversal where specially crafted sequences such as .../...// are used to bypass input sanitization and traverse directory structures on the server. The flaw is exploitable remotely over the network with no authentication required, no user interaction, and low attack complexity, making it accessible to unauthenticated attackers. The specific code path within the plugin that fails to properly sanitize file path inputs allows an attacker to read files outside the intended directory scope (Patchstack).

Impact

Successful exploitation results in unauthorized read access to files on the server, posing a confidentiality risk. There is no integrity or availability impact based on the CVSS assessment. An attacker could potentially read sensitive WordPress configuration files (e.g., wp-config.php) or other server-side files accessible to the web server process, which could expose database credentials or other secrets and facilitate further compromise (Patchstack).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.021% (0.000210), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Primer MyData for WooCommerce plugin version ≤ 4.2.8 using tools like WPScan, Shodan, or Google dorks targeting plugin-specific paths.
  2. Craft malicious request: Construct an HTTP request to a vulnerable plugin endpoint that accepts a file path parameter, embedding a path traversal sequence such as .../...// or variations thereof to escape the intended directory.
  3. Traverse directory: The crafted sequence bypasses the plugin's input sanitization, allowing the attacker to reference files outside the web root or plugin directory (e.g., ../../../../wp-config.php).
  4. Retrieve sensitive files: The server returns the contents of the targeted file, potentially exposing WordPress database credentials, secret keys, or other sensitive configuration data that can be leveraged for further attacks (Patchstack).

Indicators of compromise

  • Network: HTTP requests to plugin-related endpoints containing path traversal patterns such as .../...//, ....//, or URL-encoded equivalents (e.g., %2e%2e%2f) in file path parameters.
  • Logs: Web server access logs (Apache/Nginx) showing GET or POST requests with traversal sequences targeting the primer-mydata plugin path; HTTP 200 responses to requests referencing wp-config.php or other sensitive files.
  • File System: No file system changes expected (read-only impact), but review for unexpected access to wp-config.php or other sensitive files in server access logs.

Mitigation and workarounds

Update the Primer MyData for WooCommerce plugin to version 4.2.9 or later, which contains the patch for this vulnerability. If an immediate update is not possible, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. Site administrators should also consider restricting direct file access to sensitive directories via server configuration (e.g., .htaccess rules) as a defense-in-depth measure (Patchstack).

Additional resources

  • Patchstack — Patchstack vulnerability advisory for CVE-2025-69325
  • VulDB — VulDB vulnerability entry

Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management