The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
History

Wed, 02 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Axlethemes
Axlethemes axle Demo Importer
Weaknesses CWE-434
CPEs cpe:2.3:a:axlethemes:axle_demo_importer:*:*:*:*:*:wordpress:*:*
Vendors & Products Axlethemes
Axlethemes axle Demo Importer

Wed, 11 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
Title Axle Demo Importer <= 1.0.3 - Author+ Arbitrary File Upload
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-06-11T13:30:26.508Z

Reserved: 2025-05-19T12:46:00.475Z

Link: CVE-2025-4954

cve-icon Vulnrichment

Updated: 2025-06-11T13:30:22.472Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-10T06:15:22.403

Modified: 2025-07-02T16:11:11.290

Link: CVE-2025-4954

cve-icon Redhat

No data.