cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp01 wp01

Direction: ascending
Mar 16, 2025

WP01 – Speed, Security, SEO consultant # CVE-2025-2267

CVE, Research URL

CVE-2025-2267

Date
Mar 15, 2025
Research Description
The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due to a missing capability check and insufficient restrictions on the make_archive() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download and read the contents of arbitrary files on the server, which can contain sensitive information.
Affected versions
max 2.6.2.
Status
vulnerable
Mar 27, 2025

WP01 – Speed, Security, SEO consultant # CVE-2025-30567

CVE, Research URL

CVE-2025-30567

Date
Mar 26, 2025
Research Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wp01ru WP01 allows Path Traversal. This issue affects WP01: from n/a through 2.6.2.
Affected versions
max 2.6.2.
Status
vulnerable