CVE-2025-6722 describes a Sensitive Information Exposure vulnerability in all versions of the BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security WordPress plugin up to and including 4.5. This flaw allows unauthenticated attackers to access sensitive files like config.ini and debug.log from the automatically created bitfire_* directory if directory listing is enabled and the plugin's index.php file is missing or ignored. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity, requiring no privileges or user interaction, and resulting in a low impact on confidentiality. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bitslip6 | BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security | >= 0, <= 4.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.