Arbitrary File Upload Vulnerability in Auto Thumbnailer Plugin for WordPress
CVE-2025-12154
8.8HIGH
What is CVE-2025-12154?
The Auto Thumbnailer plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation in the uploadThumb() function. This vulnerability allows authenticated users with Contributor-level access or higher to upload potentially malicious files to the server. If exploited, this flaw may enable remote code execution and compromise the site’s integrity.
Affected Version(s)
Auto Thumbnailer * <= 1.0