PT-2025-44718 · WordPress · Wordpress Restful Content Syndication

·

CVE-2025-12171

·

Publicado

2025-11-01

·

Atualizado

2025-11-01

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress RESTful Content Syndication plugin versions 1.1.0 through 1.5.0
Description The RESTful Content Syndication plugin for WordPress is affected by a flaw that allows authenticated attackers with Author-level access or higher to upload arbitrary files to the server. This is due to missing file type validation in the ingest image() function. Successful exploitation may lead to remote code execution. The attacker requires access to a defined third-party server as specified in the plugin's settings.
Recommendations Update the RESTful Content Syndication plugin to a version later than 1.5.0.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12171

Produtos afetados

Wordpress Restful Content Syndication