This Popular WordPress Security Plugin Has a Worrying Flaw That Exposed User Data



  • WordPress Plugin Flaw Allows Low-Privilege Users to Access Sensitive Server Credentials and Files
  • CVE-2025-11705 affects plugin versions 4.23.81 and earlier; patch released October 15
  • Some 50,000 sites remain vulnerable; Administrators are urged to update immediately.

A popular WordPress plugin with over 100,000 active installations had a bug that allowed threat actors to read any file on the server, including people’s emails and, in some cases, passwords as well.

Security researchers at Wordfence reported a vulnerability in the Anti-Malware Security and Brute-Force Firewall plugin for WordPress. As the name suggests, this plugin allows site owners to scan for malware, protect their sites against brute force attacks, defend against known flaws, and more.



Leave a Comment

Your email address will not be published. Required fields are marked *