Junglewise Threat Intelligence

CVE-2025-28973: AA-Team Pro Bulk Watermark Plugin for WordPress path traversal

CVE-2025-28973 · Severity: medium · CVSS 6.5 · Published 2025-12-31

Executive brief

The Pro Bulk Watermark Plugin for WordPress is used to apply watermarks to images on WordPress sites. A path traversal vulnerability allows attackers to escape the plugin's intended directory and access sensitive files stored elsewhere on the server, potentially exposing private data, configuration files, or database credentials.

Technical details

This is a path traversal vulnerability (CWE-22) in the Pro Bulk Watermark Plugin for WordPress versions through 2.0, identified as CVE-2025-28973. The vulnerability allows an attacker with Subscriber-level privileges or higher to use directory traversal sequences (e.g., '.../...//' patterns) to escape the plugin's sandbox directory and read arbitrary files on the server. The attack is network-reachable and requires valid WordPress user authentication at the Subscriber level. An attacker can achieve unauthorized file disclosure, potentially exposing sensitive configuration, database credentials, or private files. No official patch has been released as of the advisory date; Patchstack has issued a mitigation rule to block exploitation attempts.

Affected products

  • AA-Team Pro Bulk Watermark Plugin for WordPress <= 2.0

Timeline

  • 2025-07-10: disclosed
  • 2025-12-31: advisory: CVE-2025-28973 published

References