Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

WordPress Anti-Malware Security and Brute-Force Firewall Arbitrary File Read Vulnerability

Vulnerability

A vulnerability allowing arbitrary file read has been identified in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress, affecting all versions through 4.23.81. The issue arises from a missing capability check and information exposure in several AJAX actions, which enables authenticated attackers with Subscriber-level access and above to read arbitrary files on the server that may contain sensitive information.

Impact

Exploitation of this vulnerability allows authenticated users with Subscriber-level access and above to read sensitive files on the server.

Remediation

Users are advised to update the plugin to version 4.23.83 or a newer patched version.

Added: Oct 29, 2025, 5:19 AM
Updated: Oct 29, 2025, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
7.1
remediation
7.7
relevance
0.8
threat
8.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.