8.8
CVE-2025-4954
- EPSS 0.1%
- Veröffentlicht 10.06.2025 06:00:11
- Zuletzt bearbeitet 02.07.2025 16:11:11
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Axle Demo Importer <= 1.0.3 - Authenticated (Author+) Arbitrary File Upload
The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
Mögliche Gegenmaßnahme
Axle Demo Importer: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Axle Demo Importer
Version
*-1.0.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Axlethemes ≫ Axle Demo Importer SwPlatformwordpress Version <= 1.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.267 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.