HIGH
buddydev
CVE published 2026-01-06
CVE-2025-14997
The BuddyPress Xprofile Custom Field Types plugin for WordPress has a vulnerability allowing arbitrary file deletion due to insufficient file path validation in the 'delete_field' function up to version 1.2.8. Authenticated attackers with Subscriber-level access can delete arbitrary files, potentially leading to remote code execution. This vulnerability has a high severity level and requires immediate att [truncated]