The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Axlethemes
Axlethemes axle Demo Importer |
|
Weaknesses | CWE-434 | |
CPEs | cpe:2.3:a:axlethemes:axle_demo_importer:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Axlethemes
Axlethemes axle Demo Importer |
Wed, 11 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 10 Jun 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server | |
Title | Axle Demo Importer <= 1.0.3 - Author+ Arbitrary File Upload | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-11T13:30:26.508Z
Reserved: 2025-05-19T12:46:00.475Z
Link: CVE-2025-4954

Updated: 2025-06-11T13:30:22.472Z

Status : Analyzed
Published: 2025-06-10T06:15:22.403
Modified: 2025-07-02T16:11:11.290
Link: CVE-2025-4954

No data.