Path Traversal Vulnerability in vanquish User Extra Fields Plugin
CVE-2025-69376

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 February 2026

What is CVE-2025-69376?

The vanquish User Extra Fields plugin for WordPress contains a path traversal vulnerability that allows unauthorized users to access restricted directories. This flaw affects versions from n/a through 17.0, potentially leading to unauthorized file access on the server. Users are encouraged to patch their installations promptly to mitigate risks associated with this security issue.

Affected Version(s)

User Extra Fields 0 <= 17.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.