logo

WordPress security plugin exposes private data to site subscribers

ID: 2fa7924f-2242-5924-944f-2f680df3c56c

STIX ID: report--2fa7924f-2242-5924-944f-2f680df3c56c

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-10-29

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

An authenticated low-privilege file disclosure vulnerability (CVE-2025-11705) in the Anti-Malware Security and Brute-Force Firewall WordPress plugin allows subscribers to read arbitrary server files (including wp-config.php). The developer released version 4.23.83 to add proper capability checks; roughly 50,000 sites may still be running vulnerable versions and administrators are advised to apply the patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.