Path Traversal Vulnerability in Gioni Plugin Inspector Affects WordPress Security
CVE-2025-53298

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-53298?

A Path Traversal vulnerability in the Gioni Plugin Inspector allows attackers to access files and directories that are outside the intended directory structure. This flaw can potentially lead to unauthorized access to sensitive files on the server, posing significant risk to the integrity and confidentiality of data. The vulnerability affects Plugin Inspector from version n/a through 1.5 and requires immediate attention to safeguard WordPress installations.

Affected Version(s)

Plugin Inspector <= 1.5

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Quang Bach (maysbachs) (Patchstack Alliance)
.
CVE-2025-53298 : Path Traversal Vulnerability in Gioni Plugin Inspector Affects WordPress Security