
🚨 CVE-2025-4828: Support Board <= 3.8.0 - Unauthen... Delete wp-config.php via path traversal, instant shell access - chains with CVE-2025-4855 for full unauthenticated takeo... https://zerodaysignal.com/vulnerability/CVE-2025-4828 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE‑2025‑4828, describing a path‑traversal flaw that deletes wp‑config.php and provides shell access, with chaining to CVE‑2025‑4855 for full takeover, but offers no patch info, PoC, or evidence of active exploitation.
