PT-2025-50839 · Watchtowerhq+1 · Watchtowerhq

·

CVE-2025-13972

·

Published

2025-12-11

·

Updated

2025-12-12

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WatchTowerHQ plugin for WordPress versions prior to 3.16.1
Description Insufficient path validation in the handle big object download request() function allows authenticated attackers with administrator-level access and a valid access token to read arbitrary files on the server. This is achieved via the wht download big object origin parameter, potentially exposing sensitive data such as authentication keys and database credentials.
Recommendations Update the plugin to a version newer than 3.16.0. As a temporary mitigation, restrict access to the handle big object download request() function.

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13972

Affected Products

Watchtowerhq