CVE-2025-66428: Path Traversal
Published Jan 22, 2026
·Updated
An issue with WordPress directory names in WebPros WordPress Toolkit before 6.9.1 allows privilege escalation.
Affected Software
1 affected component
Webpros WordPress Toolkit<6.9.1
Event History
Jan 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-66428?
CVE-2025-66428 has a high severity level due to its potential for privilege escalation in the WebPros WordPress Toolkit.
2
How do I fix CVE-2025-66428?
To fix CVE-2025-66428, update your WebPros WordPress Toolkit to version 6.9.1 or later.
3
What versions of WebPros WordPress Toolkit are affected by CVE-2025-66428?
CVE-2025-66428 affects all versions of WebPros WordPress Toolkit prior to 6.9.1.
4
What types of systems are vulnerable due to CVE-2025-66428?
Any system using WebPros WordPress Toolkit versions below 6.9.1 is vulnerable to CVE-2025-66428.
5
Is there a workaround for CVE-2025-66428 if I cannot update right away?
Currently, there are no documented workarounds for CVE-2025-66428, so immediate updating is recommended.