Arbitrary File Upload Vulnerability in Inline Image Upload for BBPress Plugin by WordPress
CVE-2025-2006

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 March 2025

What is CVE-2025-2006?

The Inline Image Upload functionality in the BBPress plugin for WordPress suffers from a significant security flaw related to file type validation. This vulnerability allows authenticated attackers, with a minimum of Subscriber-level access, to upload arbitrary files onto the affected site's server. Moreover, if the setting to permit guest users to create topics and replies is enabled, this vulnerability can potentially be exploited by unauthorized users as well, increasing the risk of remote code execution on the affected site.

Affected Version(s)

Inline Image Upload for BBPress * <= 1.1.19

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammad yudha
.
CVE-2025-2006 : Arbitrary File Upload Vulnerability in Inline Image Upload for BBPress Plugin by WordPress