Arbitrary File Upload Vulnerability in EM Beer Manager Plugin for WordPress
CVE-2025-11724 
8.8HIGH
What is CVE-2025-11724?
The EM Beer Manager plugin for WordPress has a vulnerability that allows authenticated users with subscriber-level access to upload arbitrary files, including malicious PHP files. This is due to insufficient file type validation in the EMBM_Admin_Untappd_Import_image() function and lack of proper authorization checks on the wp_ajax_embm-untappd-import action. An attacker can exploit this vulnerability by providing a mock HTTP server that returns specific JSON data, paving the way for remote code execution on the server.
Affected Version(s)
EM Beer Manager * <= 3.2.3