Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3294


The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all versions up to, and including, 1.2.9.1. This makes it possible for authenticated attackers, with Administrator-level access and above, to overwrite arbitrary files on the affected site's server which may make remote code execution possible assuming the files can be written to by the web server.


Published

2025-04-17T06:15:43.977

Last Modified

2025-07-09T20:03:56.407

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application benjaminrojas wp_editor < 1.2.9.2 Yes

References