Arbitrary File Upload Vulnerability in File Away Plugin for WordPress
CVE-2025-2512

9.8CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
19 March 2025

What is CVE-2025-2512?

The File Away plugin for WordPress is susceptible to arbitrary file uploads due to inadequate capability checks and a lack of file type validation within the upload() function. This vulnerability affects all versions up to and including 3.9.9.0.1. Unauthenticated attackers can exploit this flaw to upload malicious files onto the server hosting the affected site, potentially facilitating remote code execution and compromising the security of the website.

Affected Version(s)

File Away * <= 3.9.9.0.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sélim Lanouar
.