CVE-2025-12161High· 8.8▾ TwilightThe Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creation functionality in all versions up to, and including, 1.2.0. This makes it possible fo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the auto-image creation functionality in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12862Medium· 6.3A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0
CVE-2025-14583High· 7.3A flaw has been found in campcodes Online Student Enrollment System 1.0
CVE-2025-14582Medium· 4.7A vulnerability was detected in campcodes Online Student Enrollment System 1.0
CVE-2025-14530Medium· 4.7A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0
CVE-2025-14522Medium· 6.3A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c
CVE-2025-14641Medium· 4.7A flaw has been found in code-projects Computer Laboratory System 1.0