File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read

Strategic Overview

Status
Unpatched
Affected PluginFile Away
Affected Version<= 3.9.9.0.1
CVSS7.5High
CVECVE-2025-2539
View all File Away vulnerabilities

Vulnerability Overview

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-327 (Use of a Broken or Risky Cryptographic Algorithm) The product uses a broken or risky cryptographic algorithm or protocol.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C