Ver todas as ameaças

CVE-2025-2006

Alvo: Não informado

Descrição

The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the file uploading functionality in all versions up to, and including, 1.1.19. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site’s server which may make remote code execution possible. This may be exploitable by unauthenticated attackers when the “Allow guest users without accounts to create topics and replies” setting is enabled.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2025-2006
Tags
Nâo informado
Data de publicação
29/03/2025
Última atualização
08/04/2025
Pontuação em CVSS 3.0
8.8
Alto
Rolar para cima