Логотип exploitDog
bind:CVE-2025-4954
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-4954

Количество 2

Количество 2

nvd логотип

CVE-2025-4954

8 месяцев назад

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-93gr-9vgp-hf59

8 месяцев назад

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-4954

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

CVSS3: 8.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-93gr-9vgp-hf59

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

CVSS3: 8.8
0%
Низкий
8 месяцев назад

Уязвимостей на страницу