WordPress · Beeteam368 Extensions Pro · CVE-2025-6379
Name of the Vulnerable Software and Affected Versions:
BeeTeam368 Extensions Pro plugin for WordPress versions up to, and including, 2.3.4
Description:
The issue allows authenticated attackers with Subscriber-level access and above to perform actions on files outside of the originally intended directory via the `handle live fn()` function. This can be used to delete the `wp-config.php` file, potentially leading to a site takeover.
Recommendations:
For versions up to, and including, 2.3.4, consider disabling the `handle live fn()` function until a patch is available to prevent exploitation.
Restrict access to sensitive files, such as `wp-config.php`, to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.