The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed directly to file_get_contents() without sanitization. This makes it possible for authenticated attackers with Author-level permissions or higher to read arbitrary files on the server, including sensitive configuration files like /etc/passwd and wp-config.php, via the REST API. The file contents are stored in post meta and can be exfiltrated through MetForm's email confirmation feature.
History

Wed, 07 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Roxnor
Roxnor emailkit
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Roxnor
Roxnor emailkit
Woocommerce
Woocommerce woocommerce
Wordpress
Wordpress wordpress

Wed, 07 Jan 2026 04:00:00 +0000

Type Values Removed Values Added
Description The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and including, 1.6.1. This is due to missing path validation in the create_template REST API endpoint where user-controlled input from the emailkit-editor-template parameter is passed directly to file_get_contents() without sanitization. This makes it possible for authenticated attackers with Author-level permissions or higher to read arbitrary files on the server, including sensitive configuration files like /etc/passwd and wp-config.php, via the REST API. The file contents are stored in post meta and can be exfiltrated through MetForm's email confirmation feature.
Title EmailKit <= 1.6.1 - Authenticated (Author+) Arbitrary File Read via Path Traversal
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-01-07T16:14:50.860Z

Reserved: 2025-12-04T19:21:34.885Z

Link: CVE-2025-14059

cve-icon Vulnrichment

Updated: 2026-01-07T14:53:17.315Z

cve-icon NVD

Status : Received

Published: 2026-01-07T12:16:51.647

Modified: 2026-01-07T12:16:51.647

Link: CVE-2025-14059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-07T10:08:07Z