S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 2, 2025

CVE-2025-30567 Scanner

CVE-2025-30567 Scanner - Path Traversal vulnerability in WordPress WP01

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-30567
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP01 WP01 wp01 allows Path Traversal.This issue affects WP01: from n/a through <= 2.6.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP01by WP01
0
Updated Aug 22, 2026View on NVD →
Detail

WordPress WP01 is a plugin utilized primarily by website administrators and developers who need additional functionality on their WordPress sites. This plugin is integrated into WordPress for creating and managing custom features without requiring in-depth development knowledge. It is used worldwide by millions of people in various industries, from small businesses to large enterprises. WP01 assists users in adding extra features and enhancing the usability of their WordPress sites. Due to its vast use, WP01 is maintained by its developers for performance, feature updates, and security enhancements. Yet, vulnerabilities such as the path traversal vulnerability can significantly impact its use and reliability.

The path traversal vulnerability in WordPress WP01 allows unauthorized users to access sensitive files and directories stored outside the intended accessible locations. This vulnerability can potentially be exploited by malicious actors to bypass access controls and read restricted system files. Path traversal issues arise because of inadequate validation of user-supplied input paths in the software. It is often exploited via web applications due to improper validation of characters used in file paths. This vulnerability typically affects systems with exposed directories, posing a risk to data security if left unpatched. Addressing this vulnerability is crucial to secure systems employing WP01.

The technical details of the path traversal vulnerability in WP01 involve improper handling of file and directory paths. Specifically, the vulnerability is exploited through HTTP requests sent to the server with crafted inputs manipulating file paths. An attacker can issue a POST request to 'admin-ajax.php?action=wp01_generate_zip_archive' endpoint to generate a zip archive containing sensitive files. The vulnerable parameter 'path' can be manipulated to access restricted directories, such as '/etc/'. Proper filtering and sanitization of this input are lacking, allowing string manipulation like '../' to navigate file system directories freely. Subsequently, attackers can download created zip archives via a GET request.

Exploiting the path traversal vulnerability in WP01 can have severe consequences on affected systems. Malicious actors could gain access to or extract confidential files and information, leading to data breaches. This breach can consequently result in unauthorized disclosure of sensitive information, potentially damaging an organization's reputation or leading to financial losses. Additionally, attackers may leverage this vulnerability to gather intelligence about the system, preparing for further attacks. Chronic exposure increases risks of data loss and misuse, making prompt remediation critical for maintaining security.

REFERENCES

Solution Advice
  • Update WordPress WP01 plugin to the latest version to ensure patches are applied.
  • Implement strict input validation and sanitization on file paths to prevent directory traversal.
  • Restrict file access permissions to limit exposure of sensitive files and directories.
  • Regularly monitor and review logs for suspicious activity that could indicate exploitation attempts.
  • Conduct regular security assessments to identify and mitigate potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.