Path Traversal Vulnerability in WHMPress by WHMPress Inc.
CVE-2025-39491

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 May 2025

What is CVE-2025-39491?

A Path Traversal vulnerability has been identified in WHMPress, allowing unauthorized access to files on the server. This could enable attackers to exploit the flaw by manipulating file paths, potentially leading to unauthorized information disclosure. Users of WHMPress versions from 6.2 and its revisions are encouraged to review their installations and apply necessary security measures to mitigate this risk.

Affected Version(s)

WHMpress 6.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.