How CVE-2025-13320 Turns the Profile Form Into a File-Deletion Primitive
Any front-end URL that serves the WPUM account page accepts the attack: a POST with wpum_form=profile is dispatched on init and processed by account_handler(). The only gates are a logged-in session — Subscriber is enough — and the verify_account_form nonce, both trivially scriptable. When the custom avatar option is enabled, the form persists the user-controlled 'path' element of the avatar value into the _current_user_avatar_path meta with no uploads-directory check. Submitting current_user_avatar as an array makes filter_input() return false, which arms the 'no current avatar' branch and deletes the staged path through wp_delete_file(). The CVSS 6.8 rating reflects high integrity and availability impact: removing security-relevant files can enable remote code execution.
BitFire FREE Bot Protection Stops the Exploit Before WordPress Runs
This attack is pure restricted automation: a scripted, non-interactive form POST with no CAPTCHA and no JavaScript requirement. That is exactly what BitFire FREE Bot Protection is built to stop. Bot Protection classifies the client and enforces browser verification before forms and restricted actions are allowed; exploit scripts and fake browsers fail verification and cannot submit the profile form or deliver the array payload. The request is blocked before WPUM_Forms::load_posted_form() ever dispatches, so the staged path never reaches wp_delete_file(). One limitation matters for accuracy: explicitly allowlisted bots and successfully verified real browsers are not categorically stopped, so an attacker driving the form manually from a real, verified browser falls outside this layer — patching remains essential.
Patch to WP User Manager 2.9.13
Version 2.9.13 breaks the chain at two independent points. A new validate_fields() override on the profile form rejects any submission where current_user_avatar or current_user_cover is an array, eliminating both the filter_input() false-negative that arms deletion and the array 'path' injection that stages it. Before any deletion, update_account_values() now resolves the uploads basedir and throws an Exception unless realpath() of the stored path resolves inside it, so even an already-staged out-of-uploads path can no longer be deleted. The release also returns WP_Error instead of throwing from form validation and adds safe unserialization helpers (allowed_classes=false) around stored field values. Sites with the custom avatar option disabled are not exposed through the avatar branch; for everyone else, updating is the only complete fix.
If Your Site Was Affected, Investigate for Persistence
Patching closes the known path; it does not undo a deletion that already happened or prove the site is clean. File deletion is often preparatory — removing the files that enforce your security posture clears the way for deeper compromise. Run BitFire PRO Threat Hunter on every site that ran 2.9.12 or earlier with custom avatars enabled. Threat Hunter hunts the artifacts that follow a break-in: backdoor WordPress administrator accounts, hidden database triggers, long-running PHP processes, and droppers that restore malware or reinfect the site. Remove every persistence mechanism it finds, and rotate the passwords of all privileged accounts and API credentials before you consider the incident closed.
Stop Automated Exploits at the Door With BitFire
CVE-2025-13320 shows how a routine front-end form becomes a server-level attack when input is trusted. BitFire FREE Bot Protection halts the scripted delivery this exploit depends on before WordPress processes a single line of plugin code, and BitFire PRO Threat Hunter finds any persistence an earlier compromise left behind. Update WP User Manager to 2.9.13 today, deploy BitFire, and run a Threat Hunter investigation on any site that ran an affected version. Get BitFire FREE now and stop automated exploits before they start.