CVE-2025-48158

HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-xprofile-image-field allows Path Trave...

Affects 0 products across 2 vendors.

BCS5.68
CVSS 3.18.6
EPSS0.5%
Percentile38th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A Path Traversal vulnerability exists in the BuddyPress XProfile Custom Image Field plugin, allowing attackers to access arbitrary files on the server.

BSID: BS-2025-GLOBAL-245381-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-48158?
A Path Traversal vulnerability exists in the BuddyPress XProfile Custom Image Field plugin, allowing attackers to access arbitrary files on the server.
What is the CVSS score for CVE-2025-48158?
CVE-2025-48158 has CVSS 8.6 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H. EPSS: 0.5%.
Is CVE-2025-48158 actively exploited?
No confirmed active exploitation of CVE-2025-48158 as of 2026-05-30.
How do I remediate CVE-2025-48158?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-48158?
CVE-2025-48158 affects: Alex, Buddypress.
Vulnerability Details
CVE IDCVE-2025-48158
BSIDBS-2025-GLOBAL-245381-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Published2025-08-20
Last Modified2026-04-23
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress XProfile Custom Image Field buddypress-xprofile-image-field allows Path Traversal.This issue affects BuddyPress XProfile Custom Image Field: from n/a through <= 3.0.1.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by manipulating file paths in requests to the affected plugin, potentially leading to unauthorized access to sensitive files.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Alex &mdash;
Buddypress &mdash;
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 339 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashf1ba48a7ff497694b8f48e1ba2331513f44ee2cb82d1f3537ca08e8cdc190fdb140beb349e31eea787b44ce49a8ecc78a749c186f76b7897ec793bceb03a6917
Related CVEs affecting Alex
CVE-2025-48141 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje... CVE-2025-23937 8.1 Improper Control of Filename for Include/Require Statement in PHP Program ('P... CVE-2006-5459 7.5 Multiple PHP remote file inclusion vulnerabilities in Download-Engine 1.4.2 a... CVE-2006-2879 7.5 SQL injection vulnerability in newscomments.php in Alex News-Engine 1.5.0 and... CVE-2006-5291 7.5 PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.c...
View all Alex CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →