Arbitrary File Read Vulnerability in Gotham Block Extra Light Plugin for WordPress
CVE-2025-15020
6.5MEDIUM
What is CVE-2025-15020?
The Gotham Block Extra Light plugin for WordPress harbors a vulnerability allowing authenticated attackers with contributor-level access or higher to exploit the 'ghostban' shortcode. This weakness facilitates the unauthorized reading of arbitrary files on the web server, risking exposure of sensitive data. Users are advised to upgrade to the latest version to mitigate this security issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Gotham Block Extra Light * <= 1.5.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bhumividh Treloges