CVE-2025-15066 – Arbitrary File Download through Path Traversal in Innorix WP

CVE ID : CVE-2025-15066

Published : Dec. 29, 2025, 1:15 a.m. | 1 hour, 7 minutes ago

Description : Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’), Missing Authorization vulnerability in Innorix WP allows Path Traversal.This issue affects Innorix WP from All versions If the “exam” directory exists under the directory where the product is installed (ex: innorix/exam)

Severity: 6.9 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه