CVE Database /
CVE-2025-13320
CVE · Medium
CVE-2025-13320 — WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13320
|
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 |
External Control of File Name or Path |
Medium
6.8
|
< 2.9.13
|
2.9.13 |
2025-12-11 |
—
|
CVE-2025-13320
The WP User Manager plugin for WordPress contains a vulnerability that allows an authenticated attacker, with at least Subscriber-level access, to delete any file on the server. This is possible due to inadequate validation of user-supplied file paths in the plugin's profile update feature, combined with a PHP function's mishandling of array inputs. The attacker must first exploit the vulnerability in a two-step process, and the issue only affects sites that have the custom avatar setting enabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings