CVE-2025-31070

7.5

LambertGroup · HTML5 Radio Player - WPBakery Page Builder Addon

A path traversal vulnerability in the LambertGroup HTML5 Radio Player WPBakery Page Builder Addon allows unauthenticated attackers to perform arbitrary file downloads.

Executive summary

A critical path traversal vulnerability in the LambertGroup HTML5 Radio Player WPBakery Page Builder Addon enables unauthenticated attackers to access sensitive files on the host server.

Vulnerability

This is a path traversal vulnerability (CWE-22) that allows unauthenticated users to bypass directory restrictions. The flaw enables the unauthorized reading of files located outside of the intended web root directory.

Business impact

The ability for an unauthenticated attacker to download arbitrary files poses a severe risk to data confidentiality. Attackers could potentially retrieve configuration files, credentials, or sensitive system data, which may lead to a full system compromise. With a CVSS score of 7.5, this vulnerability represents a high-risk entry point for malicious actors.

Remediation

Immediate Action: Review the official Patchstack vendor advisory for the latest update; if a patch is not yet available, deactivate the plugin immediately to prevent exploitation.

Proactive Monitoring: Monitor web server access logs for suspicious requests containing directory traversal sequences, such as dot-dot-slash patterns, directed toward the plugin endpoint.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block incoming requests containing path traversal characters to mitigate the risk until a security update is applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the ease of exploitation for unauthenticated attackers, organizations should treat this vulnerability with urgency. If an update is not currently available for the HTML5 Radio Player Addon, the most effective mitigation is to disable the plugin until the vendor releases a secure version to protect the integrity of the hosting environment.

More LambertGroup CVEs

Sources

Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.