Arbitrary File Upload Vulnerability in Inline Image Upload for BBPress Plugin by WordPress
CVE-2025-2006
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 March 2025
What is CVE-2025-2006?
The Inline Image Upload functionality in the BBPress plugin for WordPress suffers from a significant security flaw related to file type validation. This vulnerability allows authenticated attackers, with a minimum of Subscriber-level access, to upload arbitrary files onto the affected site's server. Moreover, if the setting to permit guest users to create topics and replies is enabled, this vulnerability can potentially be exploited by unauthorized users as well, increasing the risk of remote code execution on the affected site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Inline Image Upload for BBPress * <= 1.1.19
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved