nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-11705 CVE-2025-11705
MEDIUM
Anti-Malware Security and Brute-Force Firewall <= 4.23.81 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
Record summary
CVE-2025-11705 has a selected CVSS score of 6.5 (medium).
Description
The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.23.81 due to a missing capability check combined with an information exposure in several GOTMLS_* AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 29, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
anti-malware_security_and_brute-force_firewallBrowse anti-malware_security_and_brute-force_firewall_project / anti-malware_security_and_brute-force_firewall | VulnCheck | Version data not supplied | |
Anti-Malware Security and Brute-Force FirewallBrowse scheeeli / Anti-Malware Security and Brute-Force FirewallDefault status: unaffected | CVE List | Through 4.23.81 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3379118/gotmls research.cleantalk.org
https://research.cleantalk.org/cve-2025-11705 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/e2c8838c-d29a-4df8-85b3-6e440ba7f962?source=cve