The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Mon, 21 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 19 Jul 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible. | |
Title | Front-end Editor < 2.3 - Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-07-19T09:23:52.758Z
Updated: 2025-07-21T16:25:25.935Z
Reserved: 2025-07-18T21:17:39.941Z
Link: CVE-2012-10019

Updated: 2025-07-21T16:25:22.140Z

Status : Awaiting Analysis
Published: 2025-07-19T10:15:22.123
Modified: 2025-07-22T13:06:07.260
Link: CVE-2012-10019

No data.