MEDIUM
liangshao
CVE published 2026-01-07
CVE-2025-14867
The Flashcard plugin for WordPress has a Path Traversal vulnerability in all versions up to and including 0.9. Authenticated attackers with contributor level access and above can read arbitrary files on the server, potentially exposing sensitive information. This vulnerability allows attackers to access files that may contain sensitive data, which could lead to further exploitation. WordPress administrato [truncated]