Arbitrary File Deletion Vulnerability in Madara Plugin for WordPress
CVE-2025-7712
9.1CRITICAL
What is CVE-2025-7712?
The Madara - Core plugin for WordPress contains a vulnerability that allows unauthenticated attackers to delete arbitrary files on the server. This occurs due to inadequate file path validation within the wp_manga_delete_zip() function across all versions up to and including 2.2.3. Malicious actors can exploit this flaw to target critical files, like wp-config.php, potentially leading to further exploitation or remote code execution.
Affected Version(s)
Madara - Core * <= 2.2.3