By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: WordPress security plugin exposes private data to site subscribers
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > WordPress security plugin exposes private data to site subscribers
Tech News

WordPress security plugin exposes private data to site subscribers

By admin 3 Min Read
Share
SHARE

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress, installed on over 100,000 sites, has a vulnerability that allows subscribers to read any file on the server, potentially exposing private information.

The plugin provides malware scanning and protection against brute-force attacks, exploitation of known plugin flaws, and against database injection attempts.

Identified as CVE-2025-11705, the vulnerability was reported to Wordfence by researcher Dmitrii Ignatyev and affects versions of the plugin 4.23.81 and earlier.

The issue stems from missing capability checks in the GOTMLS_ajax_scan() function, which processes AJAX requests using a nonce that attackers could obtain.

This oversight allows a low-privileged user, who can invoke the function, to read arbitrary files on the server, including sensitive data such as the wp-config.php configuration file that stores the database name and credentials.

With access to the database, an attacker can extract password hashes, users’ emails, posts, and other private data (and keys, salts for secure authentication).

Although the severity of the vulnerability is not considered critical, because authentication is needed for exploitation, many websites allow users to subscribe and increase their access to various sections of the site, such as comments.

Sites that offer any kind of membership or subscription, allowing users to create accounts, meet the requirement, and are vulnerable to attacks exploiting CVE-2025-11705.

Wordfence has reported the issue to the vendor, Eli, along with a validated proof-of-concept exploit, through the WordPress.org Security Team, on October 14.

On October 15, the developer released version 4.23.83 of the plugin that addresses CVE-2025-11705 by adding a proper user capability check via a new ‘GOTMLS_kill_invalid_user()’ function.

According to WordPress.org stats, roughly 50,000 website administrators have downloaded the latest version since its release, indicating that an equal number of sites are running a vulnerable version of the plugin.

Currently, Wordfence has not detected signs of exploitation in the wild, but applying the patch is strongly recommended, as the public disclosure of the issue may draw the attackers’ attention.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

You Might Also Like

Best Streaming Service of the Year: Tech Advisor Awards 2025-26

Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale

IBM warns of critical API Connect auth bypass vulnerability

IBM warns of critical API Connect auth bypass vulnerability

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

TAGGED: Information Disclosure, Plugin, Security, Vulnerability, Website, WordPress
Share This Article
Facebook Twitter Copy Link
Previous Article Barring a setback, Ravens’ Lamar Jackson is expected to make his return in Week 9 on TNF
Next Article The Microsoft Azure Outage Shows the Harsh Reality of Cloud Failures
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Best Streaming Service of the Year: Tech Advisor Awards 2025-26
Tech News
Today in History: December 31, Russian President Boris Yeltsin resigns
World News
Empty tables, sanctions-battered currency: Why Iran’s protests are different this time
Business
Meta Quest 3S Drops Back to Black Friday Pricing, Now the Cheapest Premium VR Headset
Gaming News
Want to start buying shares next week with £200 or £300? Here’s how!
Business
German influencer on New Year’s fireworks: ‘We’re collectively causing animal suffering’
World News
The Great Divide: When the mood overtakes the math
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Best Streaming Service of the Year: Tech Advisor Awards 2025-26

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Best Streaming Service of the Year: Tech Advisor Awards 2025-26
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?