---
id: CVE-2025-14867
title: >-
  The Flashcard plugin for WordPress is vulnerable to Path Traversal in all
  versions up to, and including, 0.9 via the 'source' attribute of the
  'flashcard' shortcode
summary: >-
  The Flashcard plugin for WordPress is vulnerable to Path Traversal in all
  versions up to, and including, 0.9 via the 'source' attribute of the
  'flashcard' shortcode. This makes it possible for authenticated attackers,
  with contributor le…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14867'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/flashcard/tags/0.9/flashcard.php?marks=73,109#L73
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/f4fcc6e5-1f90-41e7-8d5a-2bfe8cbf46fa?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00346
epssPercentile: 0.25717
ingestedAt: '2026-09-30T22:27:27.714Z'
---

## Overview

The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'source' attribute of the 'flashcard' shortcode. This makes it possible for authenticated attackers, with contributor level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
