Beveiligingsadvies

CVE-2025-10057

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-09-17 05:18:45
Laatst bijgewerkt 2025-09-17 12:49:25
Toegewezen door Wordfence
CVSS-score 8.8
Status PUBLISHED

Beschrijving

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.28. This is due to the write_to_customfile() function writing unfiltered PHP code to a file. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject the customFunction.php file with PHP code that can be accessed to trigger remote code execution.