Arbitrary File Upload Vulnerability in Droip Plugin for WordPress
CVE-2025-5831
8.8HIGH
What is CVE-2025-5831?
The Droip plugin for WordPress has a security flaw that allows authenticated attackers with Subscriber-level access and above to upload arbitrary files to the server. This vulnerability arises from inadequate file type validation in the make_google_font_offline() function. As a result, there's a risk of remote code execution, which can lead to severe security breaches if exploited.
Affected Version(s)
Droip * <= 2.2.0