CVE-2025-0822
MEDIUMBit Assist < 1.5.3 - Authenticated Path Traversal via fileID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-0822. PoCs published by certuscyber.
AI-analyzed exploit summary The repository contains functional exploit code for multiple WordPress plugin vulnerabilities, including SQL injection (CVE-2014-5182, CVE-2014-5185) and insecure deserialization (CVE-2020-29045). The PoCs demonstrate authentication, payload delivery, and data exfiltration.
Description
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the fileID Parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Exploits (1)
The repository contains functional exploit code for multiple WordPress plugin vulnerabilities, including SQL injection (CVE-2014-5182, CVE-2014-5185) and insecure deserialization (CVE-2020-29045). The PoCs demonstrate authentication, payload delivery, and data exfiltration.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N