CVE-2025-69376: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-69376 is a Path Traversal (Arbitrary File Deletion) vulnerability in the User Extra Fields WordPress plugin by vanquish, affecting all versions through 17.0. It allows unauthenticated, network-based attackers to delete arbitrary files outside the intended directory, potentially causing site breakage or denial of service. The vulnerability was reported on November 23, 2025, and published on February 5, 2026, with a patched version (17.1) released shortly after. It carries a CVSS v3.1 base score of 8.6 (High) (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The plugin fails to properly validate or sanitize file path inputs, allowing an attacker to supply crafted path sequences (e.g., ../) that escape the intended directory and reference arbitrary files on the server's filesystem. Because no authentication is required and attack complexity is low, exploitation can be performed remotely by any unauthenticated user with network access to the target WordPress site. No public proof-of-concept code has been identified at this time (Patchstack, Feedly).

Impact

Successful exploitation enables an unauthenticated attacker to delete arbitrary files on the web server, including WordPress core files, configuration files (e.g., wp-config.php), or other critical assets. Deletion of core files can render the website completely non-functional, resulting in a denial of service condition. The CVSS scope is marked as "Changed," indicating the impact can extend beyond the plugin itself to the broader WordPress installation and underlying server environment. Confidentiality and integrity impacts are rated None in the CVSS scoring, but the practical consequence of deleting wp-config.php could expose database credentials or enable site takeover (Patchstack).

Exploitability

There is no known public proof-of-concept exploit and no confirmed in-the-wild exploitation as of the latest available data. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the User Extra Fields plugin (versions ≤ 17.0) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/wp-user-extra-fields/readme.txt.
  2. Identify vulnerable endpoint: Locate the plugin's file-handling functionality that accepts user-supplied file path parameters without proper sanitization.
  3. Craft path traversal payload: Construct a request containing directory traversal sequences (e.g., ../../wp-config.php or ../../wp-includes/functions.php) targeting critical WordPress files.
  4. Send unauthenticated request: Submit the crafted HTTP request to the vulnerable endpoint without any authentication credentials, leveraging the plugin's lack of access controls.
  5. Achieve file deletion: The server processes the traversal path and deletes the targeted file, potentially causing site outage (if core files are removed) or enabling further compromise (e.g., deleting wp-config.php to trigger WordPress reinstallation) (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress endpoints associated with the User Extra Fields plugin containing path traversal sequences (../, %2e%2e%2f, %2e%2e/, .%2f) in parameters.
  • File System: Unexpected deletion or absence of WordPress core files (e.g., wp-config.php, files in wp-includes/ or wp-admin/); missing plugin or theme files not explained by administrative activity.
  • Logs: Web server access logs (Apache/Nginx) showing requests with encoded or literal ../ sequences targeting plugin endpoints from external IP addresses; HTTP 200 responses to file-deletion requests from unauthenticated sessions.
  • Process/Application: WordPress site returning installation wizard or database connection errors following deletion of wp-config.php; unexpected 404 errors for previously functional pages indicating missing core files (Patchstack).

Mitigation and workarounds

Update the User Extra Fields plugin to version 17.1 or later, which contains the fix for this vulnerability. If an immediate update is not possible, consider temporarily deactivating the plugin to eliminate the attack surface. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. Additionally, restrict filesystem permissions so the web server process cannot delete files outside the WordPress web root, and monitor file access logs for path traversal patterns (Patchstack).

Community reactions

Patchstack, which coordinated disclosure after the vulnerability was reported by researcher Phat RiO on November 23, 2025, classified the issue as high priority and issued a virtual mitigation rule for its users. The vulnerability was also featured in Wordfence's weekly WordPress vulnerability report for the week of February 2–8, 2026, indicating broad awareness within the WordPress security community (Wordfence, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management