cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgame-users-share-buttons game-users-share-buttons

Direction: descending
Jul 02, 2025

Game Users Share Buttons # CVE-2025-6755

CVE, Research URL

CVE-2025-6755

Date
Jun 28, 2025
Research Description
The Game Users Share Buttons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ajaxDeleteTheme() function in all versions up to, and including, 1.3.0. This makes it possible for Subscriber-level attackers to add arbitrary file paths (such as ../../../../wp-config.php) to the themeNameId parameter of the AJAX request, which can lead to remote code execution.
Affected versions
Min -, max -.
Status
vulnerable