WordPress Administrator Z Directory Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in the WordPress plugin Administrator Z, affecting versions through 2025.03.28. This vulnerability allows for directory traversal, which could enable a malicious actor to access files outside of the intended directory or determine the existence of specific files or directories.

Impact

Exploitation of this vulnerability could lead to unauthorized access to files on the server, potentially allowing for further exploitation of the website or server.

Remediation

Users of the WordPress Administrator Z plugin should update to version 2025.03.30 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.5
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.