Path Traversal Vulnerability in Custom Query Shortcode Plugin for WordPress
CVE-2025-8562
6.5MEDIUM
What is CVE-2025-8562?
The Custom Query Shortcode plugin for WordPress is susceptible to a Path Traversal vulnerability via the 'lens' parameter. This flaw allows authenticated attackers with Contributor-level access or higher to gain unauthorized access to files on the server. Consequently, sensitive information contained within these files can be exposed, posing significant risks to the integrity and confidentiality of the affected site.
Affected Version(s)
Custom Query Shortcode * <= 0.4.0