ZeroHour

CVE-2025-4954

PoC
CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
Description

The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server

Vendors
axlethemes
Products
axle demo importer
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.