Description
The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. This can be used to copy the contents of wp-config.php into a text file which can then be accessed in a browser to reveal database credentials.
Published: 2025-08-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file copy that can expose wp-config.php and database credentials
Action: Immediate Patch
AI Analysis

Impact

The WP Webhooks plugin, in all releases up to 3.3.5, accepts user‑supplied input without proper validation, allowing an unauthenticated attacker to copy arbitrary files from the web server to arbitrary destinations. This flaw can be leveraged to read the wp‑config.php file and expose database credentials, severely compromising confidentiality and potentially enabling further attacks. The vulnerability carries a CVSS score of 9.8, indicating critical severity.

Affected Systems

The vulnerability affects the WP Webhooks plugin developed by cozmoslabs, used to automate tasks within WordPress. All installations of WP Webhooks version 3.3.5 or earlier are impacted. No later versions are listed as vulnerable.

Risk and Exploitability

Given the missing authentication checks, the attack vector is likely an unauthenticated HTTP request to a plugin endpoint that processes file copy operations. Although the EPSS score is less than 1%, indicating a low current exploitation probability, the high CVSS score and the potential for credential leakage warrant urgent attention. The flaw is not listed in CISA KEV, but the impact remains critical. An attacker with network access to the site could exploit the flaw without any special credentials, leading to local file disclosure and potential compromise of the entire WordPress installation.

Generated by OpenCVE AI on April 20, 2026 at 19:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Webhooks plugin to version 3.3.6 or later so that input validation is restored
  • If upgrading immediately is not possible, disable the WP Webhooks plugin or block its endpoints using a web‑application firewall or server‑level access restrictions
  • Configure the web server to prevent external access to wp-config.php, for example by adding a deny rule in .htaccess or the server configuration

Generated by OpenCVE AI on April 20, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25429 The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. This can be used to copy the contents of wp-config.php into a text file which can then be accessed in a browser to reveal database credentials.
History

Thu, 21 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 21 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
Description The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to arbitrary locations. This can be used to copy the contents of wp-config.php into a text file which can then be accessed in a browser to reveal database credentials.
Title WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:28:22.964Z

Reserved: 2025-08-12T17:26:29.249Z

Link: CVE-2025-8895

cve-icon Vulnrichment

Updated: 2025-08-21T13:33:00.526Z

cve-icon NVD

Status : Deferred

Published: 2025-08-21T08:15:30.900

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-8895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T20:00:10Z

Weaknesses