NVIDIA Triton Flaws Allow Attackers to Seize Control of AI Servers
August 5, 2025SonicWall Warns of Gen 7 Firewall Attacks
August 5, 2025NVIDIA Triton Flaws Allow Attackers to Seize Control of AI Servers
August 5, 2025SonicWall Warns of Gen 7 Firewall Attacks
August 5, 2025Severity
High
Analysis Summary
CVE-2025-5061 CVSS:7.5
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability was partially patched in version 3.9.29.
CVE-2025-6207 CVSS:7.5
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Impact
- Code Execution
Indicators of Compromise
CVE
CVE-2025-5061
CVE-2025-6207
Affected Vendors
- WordPress
Affected Products
- vjinfotech WP Import Export Lite
Remediation
Upgrade to the latest version available from the WordPress Plugin Directory.