Arbitrary File Upload Vulnerability in Pixabay Images Plugin for WordPress
CVE-2025-4413
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 June 2025
Badges
What is CVE-2025-4413?
The Pixabay Images plugin for WordPress has a vulnerability that allows authenticated attackers with Author-level access and above to upload arbitrary files. This arises from insufficient validation of file types in the pixabay_upload function, impacting all versions up to and including 3.4. Such a flaw could potentially lead to remote code execution on the vulnerable site, creating significant security risks.
Affected Version(s)
Pixabay Images * <= 3.4
News Articles
Vulnerabilidades | INCIBE-CERT | INCIBE
CVE-2025-4413 Fecha de publicación: 18/06/2025 *** Pendiente de traducción *** The Pixabay Images plugin for WordPress is...
4 weeks ago
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 📰
First article discovered by INCIBE
Vulnerability published
Vulnerability Reserved