CVE-2025-6722
Last modified
CVE-2025-6722 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any access restrictions. This makes it possible for unauthenticated attackers to extract sensitive data from various files like config.ini, debug.log, and more when directory listing is enabled on the server and the ~/wp-content/plugins/index.php file is missing or ignored.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5 via the bitfire_* directory that automatically gets created and stores potentially sensitive files without any access restrictions. This makes it possible for unauthenticated attackers to extract sensitive data from various files like config.ini, debug.log, and more when directory listing is enabled on the server and the ~/wp-content/plugins/index.php file is missing or ignored.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-6722?
How severe is CVE-2025-6722?
How do I fix CVE-2025-6722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67188A buffer overflow vulnerability exists in TOTOLINK A950RG V4…9.8
- CVE-2025-67189A buffer overflow vulnerability exists in the setParentalRul…6.5
- CVE-2025-6719The Terms descriptions plugin for WordPress is vulnerable to…4.4
- CVE-2025-6720The Vchasno Kasa plugin for WordPress is vulnerable to unaut…5.3
- CVE-2025-67202Sidekiq-cron thru 2.3.1, an open-source scheduling add-on fo…6.1
- CVE-2025-6721The Vchasno Kasa plugin for WordPress is vulnerable to unaut…5.3
- CVE-2025-67221The orjson.dumps function in orjson thru 3.11.4 does not lim…7.5
- CVE-2025-67223The Aranda File Server (AFS) component in Aranda Software Ar…7.5
- CVE-2025-67229An improper certificate validation vulnerability exists in T…9.8
- CVE-2025-6723Chef InSpec versions up to 5.23 and before 7.0.107 creates n…5.8
- CVE-2025-67230Improper permissions in the handler for the Custom URL Schem…7.1
- CVE-2025-67231A reflected cross-site scripting (XSS) vulnerability in ToDe…5.9
Are you affected by CVE-2025-6722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
