CVE-2025-26752: WordPress VideoWhisper Live Streaming Integration plugin <= 6.2 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Path Traversal.This issue affects Broadcast Live Video: from n/a through <= 6.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26752?
CVE-2025-26752 has been rated as a critical severity due to its potential for exploitation via path traversal.
How do I fix CVE-2025-26752?
To fix CVE-2025-26752, update the VideoWhisper Live Streaming Integration plugin to version 6.3 or later.
What causes CVE-2025-26752?
CVE-2025-26752 is caused by improper limitation of a pathname that allows attackers to bypass directory restrictions.
What are the consequences of CVE-2025-26752?
Exploitation of CVE-2025-26752 can lead to unauthorized access to sensitive files on the server.
Which versions are affected by CVE-2025-26752?
CVE-2025-26752 affects all versions of VideoWhisper Live Streaming Integration from n/a through 6.2.