CVE-2025-22663: WordPress Paid Videochat Turnkey Site plugin <= 7.2.12 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Path Traversal.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.2.12.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22663?
CVE-2025-22663 is categorized with a severity level that indicates a significant risk due to path traversal vulnerabilities.
How do I fix CVE-2025-22663?
To fix CVE-2025-22663, update the videowhisper Paid Videochat Turnkey Site to the latest version beyond 7.2.12.
What software is affected by CVE-2025-22663?
CVE-2025-22663 affects videowhisper Paid Videochat Turnkey Site up to version 7.2.12 and the WordPress Paid Videochat Turnkey Site plugin up to version 7.2.12.
What type of vulnerability is CVE-2025-22663?
CVE-2025-22663 is an improper limitation of a pathname vulnerability, commonly known as a path traversal vulnerability.
Can CVE-2025-22663 lead to data exposure?
Yes, CVE-2025-22663 can potentially allow attackers to access files outside of the restricted directory, leading to data exposure.