CVE-2025-48267: Thimpress Wp Pipes
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue affects WP Pipes: from n/a through 1.4.2.
Affected products
- Thimpress Wp Pipes: before 1.4.3 (fixed in 1.4.3)
Published 2025-06-09. Last modified 2026-06-17.