Remote Code Execution Vulnerability in Copypress Rest API Plugin for WordPress
CVE-2025-8625
9.8CRITICAL
What is CVE-2025-8625?
The Copypress Rest API plugin for WordPress contains a vulnerability allowing unauthenticated attackers to execute remote code. This arises from its copyreap_handle_image() function, which lacks adequate restrictions on file types and defaults to a hard-coded JSON Web Token (JWT) signing key when no secret is set. Consequently, attackers can forge valid tokens, gain elevated privileges, and exploit the image handler to upload arbitrary files, potentially including malicious PHP scripts. This vulnerability raises significant security concerns for WordPress sites utilizing this plugin.
Affected Version(s)
Copypress Rest API 1.1 <= 1.2