WordPress GPX Viewer Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability exists in the WordPress GPX Viewer plugin, affecting versions through 2.2.11. This vulnerability allows attackers to manipulate file paths, potentially accessing files outside the intended directory.

Impact

Exploitation of this vulnerability could lead to unauthorized file access on the server, allowing attackers to read sensitive files or execute malicious scripts.

Remediation

Users of the WordPress GPX Viewer plugin should update to version 2.2.12 or later. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.