Path Traversal Vulnerability in BuddyPress XProfile Custom Image Field Plugin
CVE-2025-48158
8.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-48158?
The BuddyPress XProfile Custom Image Field plugin is susceptible to a Path Traversal vulnerability, which allows attackers to manipulate file paths and gain unauthorized access to files on the server. This flaw primarily affects versions from n/a up to 3.0.1, enabling potential file deletion and data leakage, posing significant risks to the affected sites and users.
Affected Version(s)
BuddyPress XProfile Custom Image Field <= 3.0.1