Impact
Path Traversal vulnerability exists in Quý Lê 91 Administrator Z plugin enabling attackers to manipulate path segments and retrieve arbitrary files from the server filesystem. The weakness stems from unsanitized input that allows repeated '../' patterns and additional slashes, classified as CWE‑35. The impact is potential disclosure of sensitive files and configuration data, which may lead to further compromise if the plugin runs with elevated privileges.
Affected Systems
Affected systems are websites running WordPress with the Administrator Z plugin version up to and including 2025.03.28. No specific operating systems are listed, but the vulnerability would affect any deployment where the plugin is installed within the allowed version range, including shared hosting and cloud environments.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while an EPSS score of less than 1 % suggests at most a very low exploitation probability in current data. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit it remotely by crafting a URL that triggers the plugin’s path handling routine with crafted traversal characters; however, the exact conditions for successful exploitation are not detailed in the advisory, so the risk remains moderate.
OpenCVE Enrichment
EUVD