The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1
Description
The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1
Remediation
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
---METADATA---
VENDOR: IBM
PRODUCT: Sterling B2B Integrator / Sterling File Gateway
AFFECTED_VERSIONS: Version 6 (See vendor advisory for specific sub-versions)
---END_METADATA---
Description Summary:
IBM Sterling B2B Integrator and Sterling File Gateway 6 are affected by a security vulnerability that could lead to unauthorized access or data exposure.
Executive Summary:
IBM Sterling B2B Integrator and Sterling File Gateway 6 are susceptible to a high-severity vulnerability that could compromise secure file transfer operations and sensitive business data.
Vulnerability Details
CVE-ID: CVE-2025-14031
Affected Software: IBM Sterling B2B Integrator and IBM Sterling File Gateway
Affected Versions: Version 6
Vulnerability: This vulnerability impacts the core file management and integration components of IBM Sterling products. Although the specific vulnerability type is not detailed in the summary, the CVSS score of 7.5 indicates a serious flaw, likely involving an authentication bypass or sensitive information disclosure within the web-based management interface.
Business Impact
Failure to remediate this vulnerability could result in the compromise of sensitive B2B transactions, unauthorized access to proprietary file gateways, and potential regulatory non-compliance. The CVSS score of 7.5 justifies a High severity rating, as it directly threatens the integrity of secure business-to-business communications.
Remediation Plan
Immediate Action: Administrators should immediately apply the relevant Fix Packs or security updates released by IBM for Sterling B2B Integrator and Sterling File Gateway 6.
Proactive Monitoring: Closely monitor file transfer logs and administrative access logs for any signs of anomalous behavior or unauthorized user creation.
Compensating Controls: Ensure that the management console is not exposed to the public internet and is protected by multi-factor authentication (MFA) and network-level access controls.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 19, 2026, there is no public information indicating active exploitation of this vulnerability. IBM typically provides detailed remediation guidance; users should consult the IBM Support Portal for specific patch IDs.
Analyst Recommendation
Given the critical role these products play in enterprise data exchange, the 7.5 CVSS score necessitates a rapid patching cycle. Organizations should prioritize the installation of IBM-provided updates to secure their file transfer infrastructure against potential threats.