CVE-2025-15066 – Arbitrary File Download through Path Traversal in Innorix WP
CVE ID : CVE-2025-15066
Published : Dec. 29, 2025, 1:15 a.m. | 1 hour, 7 minutes ago
Description : Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the “exam” directory exists under the directory where the product is installed (ex: innorix/exam)
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…