UNKNOWN (0.0)
    Plugin

    Directory Traversal Vulnerability in Simple CSV Table Plugin

    Published Date: 12/12/2025
    CVE ID: CVE-2025-12960

    Summary

    The Simple CSV Table plugin for WordPress contains a directory traversal vulnerability in versions up to and including 1.0.1. It allows authenticated users with Contributor-level access and above to access arbitrary files on the server by exploiting insufficient path validation in the `href` parameter of the `[csv]` shortcode.

    Vulnerability Details

    This vulnerability is a result of improper handling of file path inputs in the Simple CSV Table plugin, where the `href` parameter is used in the `[csv]` shortcode. The lack of stringent path validation before appending user input to a base directory path permits directory traversal attacks. Such an issue can be exploited by attackers to traverse directories on the server and read potentially sensitive files. These files may include crucial details like database credentials and authentication keys, which can further compromise the security of the WordPress installation. This vulnerability requires authentication, but even users with minimal access, like Contributors, could exploit it. Consequently, this could lead to unauthorized access and data leakage if not promptly addressed.

    Recommendations

    To mitigate this vulnerability, users should restrict access to the Simple CSV Table plugin features to only highly trusted users. Additionally, it’s essential to implement stricter user roles and permissions policies, ensuring that only necessary and authorized personnel have Contributor-level access. Regularly monitor server logs for unusual file access patterns and consider deploying a Web Application Firewall (WAF) to block malicious traversal attempts.

    Available Fixes

    Last Updated: 12/13/2025
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2025 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More