Arbitrary File Upload Vulnerability in Pixabay Images Plugin for WordPress
CVE-2025-4413
8.8HIGH
What is CVE-2025-4413?
The Pixabay Images plugin for WordPress has a vulnerability that allows authenticated attackers with Author-level access and above to upload arbitrary files. This arises from insufficient validation of file types in the pixabay_upload function, impacting all versions up to and including 3.4. Such a flaw could potentially lead to remote code execution on the vulnerable site, creating significant security risks.
Affected Version(s)
Pixabay Images * <= 3.4