Path Traversal Vulnerability in Section Widget by WordPress
CVE-2025-46441

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 May 2025

What is CVE-2025-46441?

The Section Widget plugin for WordPress contains a path traversal vulnerability that could allow attackers to exploit file system access. This issue potentially enables unauthorized access to sensitive files outside the intended directory scope. The vulnerability exists in versions from n/a up to and including 3.3.1. It is crucial for users to update their installations and implement security best practices to mitigate risks.

Affected Version(s)

Section Widget <= 3.3.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.
CVE-2025-46441 : Path Traversal Vulnerability in Section Widget by WordPress