Path Traversal Vulnerability in Zombify Plugin for WordPress
CVE-2025-8385
6.8MEDIUM
What is CVE-2025-8385?
The Zombify plugin for WordPress is susceptible to a Path Traversal vulnerability due to inadequate input validation in the zf_get_file_by_url function. This flaw allows authenticated users, even those with subscriber-level access, to exploit the vulnerability and access arbitrary files on the server, including sensitive files like /etc/passwd. Exploiting this vulnerability necessitates a race condition, as the generated file is quickly deleted, making it crucial for site admins to address this issue promptly.
Affected Version(s)
Zombify 0 <= 1.7.5