CVE-2025-6381

HIGH

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes it possible fo...

Affects 1 product across 1 vendor.

BCS6.59
CVSS 3.18.8
EPSS0.7%
Percentile51th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-36: CWE-36
Related Attack Patterns (CAPEC)
CAPEC-597 Absolute Path Traversal
via CWE-36

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with Subscriber-level access and above to perform actions on files outside of the intended directory, including deletion of critical files like wp-config.php.

BSID: BS-2025-GLOBAL-038411-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-6381?
The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with Subscriber-level access and above to perform actions on files outside of the intended directory, including deletion of critical files like wp-config.php.
What is the CVSS score for CVE-2025-6381?
CVE-2025-6381 has CVSS 8.8 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.7%.
Is CVE-2025-6381 actively exploited?
No confirmed active exploitation of CVE-2025-6381 as of 2026-05-30.
How do I remediate CVE-2025-6381?
Priority: IMMEDIATE.
What systems are affected by CVE-2025-6381?
CVE-2025-6381 affects: Beeteam368.
Vulnerability Details
CVE IDCVE-2025-6381
BSIDBS-2025-GLOBAL-038411-H BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published2025-06-28
Last Modified2025-07-07
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory. This vulnerability can be used to delete the wp-config.php file, which can be leveraged into a site takeover.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the handle_remove_temp_file() function of the BeeTeam368 Extensions plugin for WordPress. Attackers can exploit this by manipulating file paths to access and delete files outside the plugin's intended directory.

Exploitation Likelihood: HIGH

Affected Products
VendorProductFixed Version
Beeteam368 Vidmov
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 392 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashe2b530f6dee08f01f13fbc0845ab2ccb46a5de5597a6ba000f3db439a21c6aaf4f054bcd8c6f146035e8a85bada42b00cd0a7419d607388705fd319dd252307c
Related CVEs affecting Beeteam368
CVE-2025-25174 10.0 Improper Control of Filename for Include/Require Statement in PHP Program ('P... CVE-2025-6379 8.8 The BeeTeam368 Extensions Pro plugin for WordPress is vulnerable to Directory... CVE-2025-6423 8.8 The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary fil... CVE-2025-25172 8.1 Improper Control of Filename for Include/Require Statement in PHP Program ('P... CVE-2025-67914 7.7 Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows ...
View all Beeteam368 CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →