CVE-2025-60223
Deferred Deferred - Pending Action
Subscriber Arbitrary File Deletion in WPBot Pro WordPress Chatbot

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack wpbot_pro to 13.6.5 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

The vulnerability affects WPBot Pro Wordpress Chatbot Plugin versions 13.6.5 and below and allows arbitrary file deletion, which can cause website malfunction or breakage.

As there is no official patch available yet, immediate mitigation involves applying the Patchstack mitigation rule to block potential attacks.

Other recommended steps include updating the plugin when a fix is released or seeking assistance from a hosting provider or web developer.

Executive Summary

CVE-2025-60223 is an Arbitrary File Deletion vulnerability found in the WPBot Pro WordPress Chatbot Plugin versions 13.6.5 and below.

This vulnerability allows attackers to delete critical files from a website using the affected plugin, which can cause the website to malfunction or break entirely.

It is considered a high-priority and highly dangerous flaw with a CVSS score of 7.7, and it may be targeted in mass-exploit campaigns.

Impact Analysis

Exploitation of this vulnerability can lead to deletion of important files on your website, potentially causing it to malfunction or become completely inoperable.

This can result in downtime, loss of data, and disruption of services provided by your website.

Since the vulnerability is highly dangerous and may be widely targeted, it poses a significant risk to website stability and security.

Detection Guidance

There is no specific information provided about detection methods or commands to identify this vulnerability on your network or system.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-60223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart