Vulnerability Database

313,825

Total vulnerabilities in the database

CVE-2025-12496

The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.203 via the file parameter. This makes it possible for authenticated attackers, with Custom-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. On a servers that have allow_url_fopen enabled, this issue allows for Server-Side Request Forgery

  • Published: Dec 17, 2025
  • Updated: Dec 18, 2025
  • CVE: CVE-2025-12496
  • Severity: Low
  • Exploit:

CVSS v3:

  • Severity: Low
  • Score: 4.9
  • AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N