Full Path Disclosure Vulnerability in Birth Chart Compatibility Plugin for WordPress
CVE-2025-6082

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 July 2025

What is CVE-2025-6082?

The Birth Chart Compatibility plugin for WordPress suffers from a Full Path Disclosure vulnerability in all versions up to and including 2.0. This vulnerability arises from inadequate measures to prevent direct access to the plugin's index.php file, which can trigger an error and expose the complete file path of the web application to unauthenticated attackers. While the exposed information alone may not be harmful, it can serve as a stepping stone for more sophisticated attacks if combined with other vulnerabilities.

Affected Version(s)

Birth Chart Compatibility * <= 2.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amin Beheshti
.
CVE-2025-6082 : Full Path Disclosure Vulnerability in Birth Chart Compatibility Plugin for WordPress