CVE-2025-2539

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:file_away_project:file_away:*:*:*:*:*:wordpress:*:*

History

11 Aug 2025, 15:00

Type Values Removed Values Added
Summary
  • (es) El complemento File Away para WordPress es vulnerable al acceso no autorizado a datos debido a la falta de una comprobación de capacidad en la función ajax() en todas las versiones hasta la 3.9.9.0.1 incluida. Esto permite que atacantes no autenticados, aprovechando un algoritmo débil reversible, lean el contenido de archivos arbitrarios en el servidor, que pueden contener información confidencial.
CPE cpe:2.3:a:file_away_project:file_away:*:*:*:*:*:wordpress:*:*
First Time File Away Project file Away
File Away Project
References () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_encrypted.php - () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_encrypted.php - Product
References () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_stats.php - () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_stats.php - Product
References () https://wordpress.org/plugins/file-away/#developers - () https://wordpress.org/plugins/file-away/#developers - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/5b23bd5c-db27-4d63-8461-1f36958a2ff6?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/5b23bd5c-db27-4d63-8461-1f36958a2ff6?source=cve - Third Party Advisory

20 Mar 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 12:15

Updated : 2025-08-11 15:00


NVD link : CVE-2025-2539

Mitre link : CVE-2025-2539

CVE.ORG link : CVE-2025-2539


JSON object : View

Products Affected

file_away_project

  • file_away
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm