Arbitrary File Deletion Vulnerability in Attachment Manager Plugin for WordPress
CVE-2025-7643
9.1CRITICAL
What is CVE-2025-7643?
The Attachment Manager plugin for WordPress is susceptible to arbitrary file deletion due to inadequate file path validation within its handle_actions() function. This vulnerability affects all versions up to and including 2.1.2, enabling unauthenticated attackers to delete arbitrary files from the server. Such exploitation carries the potential for severe consequences, including remote code execution, especially if critical files like wp-config.php are targeted and removed.
Affected Version(s)
Attachment Manager * <= 2.1.2