Rewterz
NVIDIA Triton Flaws Allow Attackers to Seize Control of AI Servers
August 5, 2025
Rewterz
SonicWall Warns of Gen 7 Firewall Attacks
August 5, 2025

Multiple WordPress Plugins Vulnerabilities

Severity

High

Analysis Summary

CVE-2025-5061 CVSS:7.5

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability was partially patched in version 3.9.29.

CVE-2025-6207 CVSS:7.5

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Impact

  • Code Execution

Indicators of Compromise

CVE

  • CVE-2025-5061

  • CVE-2025-6207

Affected Vendors

  • WordPress

Affected Products

  • vjinfotech WP Import Export Lite

Remediation

Upgrade to the latest version available from the WordPress Plugin Directory.

CVE-2025-5061

CVE-2025-6207