BeeTeam368 Extensions <= 2.3.4 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion

2025-06-27 14:26
Tonn

Strategic Overview

Status
Patched in 2.3.5
Affected PluginBeeTeam368 Extensions
Affected Version<= 2.3.4
CVSS8.8High
CVECVE-2025-6381
View all BeeTeam368 Extensions vulnerabilities

Vulnerability Overview

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory. This vulnerability can be used to delete the wp-config.php file, which can be leveraged into a site takeover.

Technical Analysis

REMEDIATION: Update to version 2.3.5, or a newer patched version --- IDENTIFIER: CWE-36 (Absolute Path Traversal) The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as /abs/path that can resolve to a location that is outside of that directory.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C