CVE-2025-47513
WordPress Infocob CRM Forms plugin <= 2.4.0 - Arbitrary File Download vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CRM Forms infocob-crm-forms allows Path Traversal.This issue affects Infocob CRM Forms: from n/a through <= 2.4.0.
| CWE | CWE-22 |
| Vendor | james laforge |
| Product | infocob crm forms |
| Published | May 23, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for james laforge infocob crm forms
Be the first to know when new unknown vulnerabilities affecting james laforge infocob crm forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
James Laforge / Infocob CRM Forms
0 โค 2.4.0
References
Credits
Martino Spagnuolo (r3verii) | Patchstack Bug Bounty Program