Arbitrary File Upload Vulnerability in WP Import Export Lite Plugin for WordPress
CVE-2025-5061

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 August 2025

What is CVE-2025-5061?

The WP Import Export Lite plugin for WordPress has a vulnerability due to inadequate file type validation within the 'wpie_parse_upload_data' function. This flaw allows authenticated attackers with Subscriber-level access or higher, assuming appropriate permissions granted by an Administrator, to upload arbitrary files to the server. This potential attack could lead to remote code execution, making it critical for site administrators to ensure they are using the latest version, as a partial fix was applied in version 3.9.29. Site owners should prioritize reviewing their plugin's configuration and access controls to mitigate risks associated with this vulnerability.

Affected Version(s)

WP Import Export Lite * <= 3.9.29

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincent Fourcade
.
CVE-2025-5061 : Arbitrary File Upload Vulnerability in WP Import Export Lite Plugin for WordPress