Pro Bulk Watermark Plugin for WordPress <= 2.0 - Authenticated (Subscriber+) Path Traversal
medium
The pro-watermark theme for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 4.3
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 25, 2025
CVE-2025-4956 on NVD →
Pro Bulk Watermark Plugin for WordPress <= 2.0 - Authenticated (Subscriber+) Path Traversal
medium
The Pro Bulk Watermark Plugin for WordPress plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 4.3
- Affected:
- up to 2.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 10, 2025
CVE-2025-28973 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database