Directory Traversal Vulnerability in BeeTeam368 Extensions Plugin for WordPress
CVE-2025-6381
8.8HIGH
What is CVE-2025-6381?
The BeeTeam368 Extensions plugin for WordPress is susceptible to a Directory Traversal vulnerability due to improper validation in the handle_remove_temp_file() function. This allows authenticated users with Subscriber-level privileges or higher to manipulate files outside the intended directory structure. An attacker could exploit this vulnerability to delete critical files like wp-config.php, potentially leading to a complete site takeover.
Affected Version(s)
BeeTeam368 Extensions * <= 2.3.4