Publitio WordPress Plugin Path Traversal Vulnerability Allowing Arbitrary File Download

Vulnerability

A path traversal vulnerability has been identified in the Publitio WordPress plugin, allowing arbitrary file downloads. This issue affects versions through 2.2.0. The vulnerability arises from improper restrictions on pathname navigation, enabling unauthorized access to files on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized downloading of files from the affected website, including sensitive information such as login credentials or backup files.

Remediation

Patchstack has issued a virtual patch to mitigate this vulnerability by blocking attacks until an official fix is available. Users can activate this virtual patch through the Patchstack service.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.