Unrestricted File Upload Vulnerability in FW Food Menu by Fastw3b LLC
CVE-2025-49447

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49447?

The FW Food Menu plugin by Fastw3b LLC presents a significant risk due to its vulnerability allowing unrestricted file uploads. This flaw enables attackers to upload potentially harmful files, which could lead to unauthorized access or manipulation of system resources. With affected versions ranging from 'n/a' through 6.0.0, it is crucial for users of this plugin to take immediate protective measures to secure their environments against possible exploitation.

Affected Version(s)

FW Food Menu <= 6.0.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.