
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69376 is a Path Traversal (Arbitrary File Deletion) vulnerability in the User Extra Fields WordPress plugin by vanquish, affecting all versions through 17.0. It allows unauthenticated, network-based attackers to delete arbitrary files outside the intended directory, potentially causing site breakage or denial of service. The vulnerability was reported on November 23, 2025, and published on February 5, 2026, with a patched version (17.1) released shortly after. It carries a CVSS v3.1 base score of 8.6 (High) (Patchstack, Feedly).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The plugin fails to properly validate or sanitize file path inputs, allowing an attacker to supply crafted path sequences (e.g., ../) that escape the intended directory and reference arbitrary files on the server's filesystem. Because no authentication is required and attack complexity is low, exploitation can be performed remotely by any unauthenticated user with network access to the target WordPress site. No public proof-of-concept code has been identified at this time (Patchstack, Feedly).
Successful exploitation enables an unauthenticated attacker to delete arbitrary files on the web server, including WordPress core files, configuration files (e.g., wp-config.php), or other critical assets. Deletion of core files can render the website completely non-functional, resulting in a denial of service condition. The CVSS scope is marked as "Changed," indicating the impact can extend beyond the plugin itself to the broader WordPress installation and underlying server environment. Confidentiality and integrity impacts are rated None in the CVSS scoring, but the practical consequence of deleting wp-config.php could expose database credentials or enable site takeover (Patchstack).
There is no known public proof-of-concept exploit and no confirmed in-the-wild exploitation as of the latest available data. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Feedly).
/wp-content/plugins/wp-user-extra-fields/readme.txt.../../wp-config.php or ../../wp-includes/functions.php) targeting critical WordPress files.wp-config.php to trigger WordPress reinstallation) (Patchstack).../, %2e%2e%2f, %2e%2e/, .%2f) in parameters.wp-config.php, files in wp-includes/ or wp-admin/); missing plugin or theme files not explained by administrative activity.../ sequences targeting plugin endpoints from external IP addresses; HTTP 200 responses to file-deletion requests from unauthenticated sessions.wp-config.php; unexpected 404 errors for previously functional pages indicating missing core files (Patchstack).Update the User Extra Fields plugin to version 17.1 or later, which contains the fix for this vulnerability. If an immediate update is not possible, consider temporarily deactivating the plugin to eliminate the attack surface. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. Additionally, restrict filesystem permissions so the web server process cannot delete files outside the WordPress web root, and monitor file access logs for path traversal patterns (Patchstack).
Patchstack, which coordinated disclosure after the vulnerability was reported by researcher Phat RiO on November 23, 2025, classified the issue as high priority and issued a virtual mitigation rule for its users. The vulnerability was also featured in Wordfence's weekly WordPress vulnerability report for the week of February 2–8, 2026, indicating broad awareness within the WordPress security community (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."