Логотип exploitDog
bind:CVE-2025-12057
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-12057

Количество 2

Количество 2

nvd логотип

CVE-2025-12057

3 месяца назад

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-5h9q-jf3c-852w

3 месяца назад

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-12057

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-5h9q-jf3c-852w

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

CVSS3: 9.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу