PT-2025-30372 · WordPress · Foxypress

CVE-2012-10020

·

Published

2025-07-22

·

Updated

2025-12-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FoxyPress versions up to 0.4.2.1
Description The FoxyPress plugin for WordPress is susceptible to arbitrary file uploads due to insufficient file type validation in the uploadify.php file. This allows unauthenticated attackers to upload arbitrary files to the affected site's server, potentially enabling remote code execution.
Recommendations Update FoxyPress to a version later than 0.4.2.1.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-10020

Affected Products

Foxypress