Arbitrary File Upload Vulnerability in User Submitted Posts Plugin for WordPress
CVE-2019-25138
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2019-25138?
The User Submitted Posts plugin for WordPress contains a vulnerability that allows unauthenticated attackers to upload arbitrary files due to insufficient file type validation in its usp_check_images function. This flaw can lead to the potential for remote code execution on the server. Users of affected versions, up to and including 20190312, are encouraged to update their plugins to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
User Submitted Posts β Enable Users to Submit Posts from the Front End * < 20190426
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved