9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up to, and including, 3.7. This is due to a discrepancy between the extension validation in `getExtensionForURL()` which operates on URL-decoded paths, and `appendNormalized()` which strips everything after a null byte before constructing the filesystem path. This makes it possible for unauthenticated attackers to read arbitrary files from the webroot, including wp-config.php, by appending a double URL-encoded null byte (%2500) followed by an allowed extension (.txt) to the file path.
AI Analysis
Unauthenticated Arbitrary File Read via null byte injection
Basic Information
ID
CVE-2025-14388
Source
Wordfence
Published
Dec 23, 2025 at 09:20
Affected Product
Vendor
kiboit
Product
PhastPress
Version
*
Affected Versions
kiboit PhastPress *
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
kiboit
Product
PhastPress
Version
3.7 and below
References
- www.wordfence.com /threat-intel/vulnerabilities/id/eec9bbc0-5a68-4624-a672-bd6227d6fa45
- plugins.trac.wordpress.org /browser/phastpress/tags/3.6/sdk/phast.php
- plugins.trac.wordpress.org /browser/phastpress/tags/3.6/sdk/phast.php
- plugins.trac.wordpress.org /browser/phastpress/tags/3.6/sdk/phast.php
- plugins.trac.wordpress.org /browser/phastpress/tags/3.6/sdk/phast.php
- plugins.trac.wordpress.org /changeset/3418139