Arbitrary File Upload Vulnerability in WP3D Model Import Viewer Plugin for WordPress
CVE-2025-13094
8.8HIGH
What is CVE-2025-13094?
The WP3D Model Import Viewer plugin for WordPress contains a vulnerability that allows authenticated attackers with Author-level access or higher to upload arbitrary files to the server due to insufficient validation of file types in the handle_import_file() function. This flaw can potentially lead to remote code execution, posing a significant security risk to websites using the plugin unless they are updated to a patched version.
Affected Version(s)
WP3D Model Import Viewer * <= 1.0.7