CyberRota
← Ana sayfaya dön

CVE-2018-25325

HIGH · CVSS 7.5 EPSS %0.61 Public Exploit

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-17T13:16:43.923 · Çekilme zamanı: 2026-06-16T12:01:39.851002+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

Public Exploit Sinyali

Bu CVE için açıklama veya referanslarda public exploit / PoC / GitHub / Metasploit sinyali tespit edildi.

Harici Güvenlik Referansları

Not: Bu bağlantılar yalnızca güvenlik araştırması ve doğrulama amacıyla listelenmiştir.

CVE
CVE-2018-25325
Severity
HIGH
CVSS
7.5
EPSS
%0.61

Orijinal NVD Açıklaması

Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unescaped filenames through the delete_export_file AJAX action. Attackers can craft POST requests with directory traversal sequences in the filename parameter to delete sensitive files like wp-config.php outside the intended export directory.