Arbitrary File Upload Vulnerability in WP移行専用プラグイン for CPI
CVE-2025-11170
9.8CRITICAL
What is CVE-2025-11170?
The WP移行専用プラグイン for CPI, designed for WordPress environments, suffers from an arbitrary file upload vulnerability due to inadequate validation of file types within the Cpiwm_Import_Controller::import function. This security flaw exists in all versions up to and including 1.0.2, enabling unauthenticated attackers to upload malicious files to the server hosting the affected site, which could subsequently lead to potential remote code execution. Website administrators must apply necessary updates to mitigate this risk.
Affected Version(s)
WP移行専用プラグイン for CPI * <= 1.0.2