CVE-2025-6082

MEDIUM

Birth Chart Compatibility <2.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-6082. PoCs published by Byte Reaper, byteReaper77.

AI-analyzed exploit summary This exploit targets a Full Path Disclosure vulnerability in the Birth Chart Compatibility WordPress plugin (v2.0 or earlier). It sends an HTTP GET request to the plugin's index.php endpoint and parses the response for filesystem path disclosures, which can aid in further attacks.

Description

The Birth Chart Compatibility plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to insufficient protection against directly accessing the plugin's index.php file, which causes an error exposing the full path. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

Exploits (2)

exploitdb WORKING POC
by Byte Reaper · cwebappsmultiple
https://www.exploit-db.com/exploits/52419

This exploit targets a Full Path Disclosure vulnerability in the Birth Chart Compatibility WordPress plugin (v2.0 or earlier). It sends an HTTP GET request to the plugin's index.php endpoint and parses the response for filesystem path disclosures, which can aid in further attacks.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Birth Chart Compatibility WordPress Plugin <= 2.0
No auth needed
Prerequisites: Target URL with vulnerable plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by byteReaper77 · poc
https://github.com/byteReaper77/CVE-2025-6082

This is a functional Proof-of-Concept exploit for CVE-2025-6082, targeting a Full Path Disclosure vulnerability in the 'Birth Chart Compatibility' WordPress plugin (versions ≤ 2.0). The exploit sends an HTTP GET request to the plugin’s index.php endpoint and parses the response for PHP warnings or errors to extract the server’s filesystem path.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Birth Chart Compatibility WordPress plugin (versions ≤ 2.0)
No auth needed
Prerequisites: Target must have the vulnerable 'Birth Chart Compatibility' WordPress plugin installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 5.3
EPSS 0.0539
EPSS Percentile 90.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
mia4/Birth Chart Compatibility < 2.0
Published Jul 22, 2025
Tracked Since Feb 18, 2026