The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE
Metrics
Affected Vendors & Products
References
History
Thu, 20 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Wed, 19 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 19 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE | |
| Title | WavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-11-19T06:00:05.080Z
Updated: 2025-11-19T19:28:46.929Z
Reserved: 2025-10-22T07:35:53.569Z
Link: CVE-2025-12057
Updated: 2025-11-19T19:28:02.867Z
Status : Awaiting Analysis
Published: 2025-11-19T06:15:45.490
Modified: 2025-11-19T20:15:47.977
Link: CVE-2025-12057
No data.