Arbitrary File Read Vulnerability in Anti-Malware Security and Brute-Force Firewall Plugin for WordPress
CVE-2025-11705

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 October 2025

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-11705?

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress contains a vulnerability that enables authenticated attackers, with at least Subscriber-level access, to exploit a lack of capability checks. This flaw, found in multiple AJAX actions, allows for arbitrary file reading, potentially exposing sensitive information stored on the server. This could lead to further attacks or data leakage if not promptly addressed.

Affected Version(s)

Anti-Malware Security and Brute-Force Firewall * <= 4.23.81

News Articles

WordPress security plugin exposes private data to site subscribers

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress, installed on over 100,000 sites, has a vulnerability that allows subscribers to read any file on the server, potentially exposing private information.

4 days ago

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.