CVE-2018-25326
Published: 17 May 2026
Summary
CVE-2018-25326 is a high-severity Path Traversal (CWE-22) vulnerability in Com (inferred from references). Its CVSS base score is 7.5 (High).
Operationally, ranked in the top 33.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Validates pathnames and filenames to prevent traversal outside intended directories.
NVD Description
Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting directory traversal sequences in the file_name parameter. Attackers can send POST requests to gdrive-ajaxs.php with the ajaxstype parameter set to…
more
del_fl_bkp and file_name containing traversal sequences ../../wp-config.php to access sensitive configuration files.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)