CVE-2025-11705: gotmls
## The Exploit A Subscriber-level WordPress user (the lowest authenticated role) can read arbitrary files from the server by sending an unauthenticated AJAX request to the plugin's file-read handlers. ```http POST /wp-admin/admin-ajax.php...
Read article →