8.8

CVE-2025-4954

Exploit

Axle Demo Importer <= 1.0.3 - Author+ Arbitrary File Upload

Axle Demo Importer <= 1.0.3 - Authenticated (Author+) Arbitrary File Upload

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
Mögliche Gegenmaßnahme
Axle Demo Importer: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AxlethemesAxle Demo Importer SwPlatformwordpress Version <= 1.0.3
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Axle Demo Importer
Version *-1.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.385
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://wpscan.com/vulnerability/673f35ff-e1d5-4099-86e7-8b6e3e410ef8/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/fe8b6a16-0a39-42fd-bb0f-9114ec08a885
Third Party Advisory