Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA aviation-weather-from-noaa allows Path Traversal.This issue affects Aviation Weather from NOAA: from n/a through <= 0.7.2.
Published: 2025-07-04
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows an attacker to delete arbitrary files from a WordPress site by exploiting a path traversal issue in the Aviation Weather from NOAA plugin’s file handling logic. Classified as CWE‑22, the vulnerability carries a CVSS score of 7.7, indicating that it presents a high‑severity risk capable of undermining the integrity of the site and its data. The description does not specify the precise conditions for exploitation, but the core weakness is the ability to reference any pathname relative to the plugin’s working directory, enabling deletion of any file the WordPress process can access.

Affected Systems

WordPress installations that include the Aviation Weather from NOAA plugin by machouinard at version 0.7.2 or earlier are affected. No additional WordPress core or PHP version constraints are listed, so the risk applies broadly to any configuration running the vulnerable plugin.

Risk and Exploitability

The EPSS score is reported as less than 1 %, suggesting that exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS rating means that if an attacker can reach the deletion functionality—potentially through a publicly exposed endpoint—they could remove critical files or assets, resulting in a denial of service or persistence of malicious content. The absence of an explicit authentication requirement in the description implies that the exploit could be performed by any user who can trigger the vulnerable operation.

Generated by OpenCVE AI on May 2, 2026 at 08:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Aviation Weather from NOAA plugin to a version newer than 0.7.2, which removes the path traversal logic.
  • If an upgrade cannot be applied immediately, restrict the deletion function by revoking the relevant capability from lower‑privileged roles or block unauthenticated access to the endpoint with web‑server rules.
  • After addressing the vulnerability, perform a file‑integrity scan and restore any deleted files from recent backups.

Generated by OpenCVE AI on May 2, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19972 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA aviation-weather-from-noaa allows Path Traversal.This issue affects Aviation Weather from NOAA: from n/a through <= 0.7.2.
Title WordPress Aviation Weather from NOAA <= 0.7.2 - Arbitrary File Deletion Vulnerability WordPress Aviation Weather from NOAA plugin <= 0.7.2 - Arbitrary File Deletion Vulnerability
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Mon, 07 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Jul 2025 11:30:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Weather from NOAA allows Path Traversal. This issue affects Aviation Weather from NOAA: from n/a through 0.7.2.
Title WordPress Aviation Weather from NOAA <= 0.7.2 - Arbitrary File Deletion Vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.012Z

Reserved: 2025-03-11T08:10:36.161Z

Link: CVE-2025-28980

cve-icon Vulnrichment

Updated: 2025-07-07T14:40:38.740Z

cve-icon NVD

Status : Deferred

Published: 2025-07-04T12:15:27.233

Modified: 2026-04-23T15:26:43.247

Link: CVE-2025-28980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T08:30:26Z

Weaknesses