Arbitrary File Deletion in Wptobe-Memberships Plugin for WordPress
CVE-2025-9048
8.1HIGH
What is CVE-2025-9048?
The Wptobe-Memberships plugin for WordPress faces a significant vulnerability allowing authenticated users with Subscriber-level access or higher to delete arbitrary files from the server. This vulnerability arises from inadequate validation of file paths in the del_img_ajax_call() function, potentially enabling attackers to invoke remote code execution by targeting critical files, such as wp-config.php. Users of the affected versions should take immediate action to secure their installations.
Affected Version(s)
Wptobe-memberships * <= 3.4.2