Path Traversal Vulnerability in Easy Video Player by FWDesign
CVE-2025-28955

7.5HIGH

What is CVE-2025-28955?

A vulnerability in FWDesign’s Easy Video Player for WordPress and WooCommerce enables attackers to exploit a path traversal flaw. This means that unauthorized users can potentially access restricted directories on the server, leading to the exposure of sensitive files. The issue affects versions from n/a through 10.0, raising significant security concerns for sites employing this plugin.

Affected Version(s)

Easy Video Player Wordpress & WooCommerce <= 10.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3 (Patchstack Alliance)
.
CVE-2025-28955 : Path Traversal Vulnerability in Easy Video Player by FWDesign