CVE-2025-2539

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:file_away_project:file_away:*:*:*:*:*:wordpress:*:*

History

11 Aug 2025, 15:00

Type Values Removed Values Added
First Time File Away Project file Away
File Away Project
CPE cpe:2.3:a:file_away_project:file_away:*:*:*:*:*:wordpress:*:*
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/5b23bd5c-db27-4d63-8461-1f36958a2ff6?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/5b23bd5c-db27-4d63-8461-1f36958a2ff6?source=cve - Third Party Advisory
References () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_stats.php - () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_stats.php - Product
References () https://wordpress.org/plugins/file-away/#developers - () https://wordpress.org/plugins/file-away/#developers - Product
References () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_encrypted.php - () https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_encrypted.php - Product

20 Mar 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 12:15

Updated : 2025-08-11 15:00


NVD link : CVE-2025-2539

Mitre link : CVE-2025-2539


JSON object : View

Products Affected

file_away_project

  • file_away
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm