Path Traversal Vulnerability in Include URL Plugin by WordPress
CVE-2025-30594
6.5MEDIUM
What is CVE-2025-30594?
A vulnerability has been identified in the Include URL plugin for WordPress that allows unauthorized access to files outside of the intended directory through a path traversal attack. This security flaw affects all versions from its initial release up to 0.3.5. By exploiting this vulnerability, an attacker can potentially download arbitrary files from the server, which may lead to the exposure of sensitive information.
Affected Version(s)
Include URL <= 0.3.5