---
id: CVE-2025-8889
title: >-
  The Compress & Upload WordPress plugin before 1.0.5 does not properly validate
  uploaded files, allowing high privilege users such as admin to upload
  arbitrary files on the server even when they should not be allowed to (for
  example in mu…
summary: >-
  The Compress & Upload WordPress plugin before 1.0.5 does not properly validate
  uploaded files, allowing high privilege users such as admin to upload
  arbitrary files on the server even when they should not be allowed to (for
  example in mu…
severity: low
cvss: 3.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-434
vendor: eliehanna
product: compress_&_upload
affected:
  - compress_&_upload < 1.0.5
patched:
  - compress_&_upload 1.0.5
published: '2025-09-09'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8889'
references:
  - url: 'https://wpscan.com/vulnerability/5d84a577-62aa-4aa2-ac39-b146eae65243/'
    label: contact@wpscan.com
tags:
  - nvd
  - exploit-available
epss: 0.00287
epssPercentile: 0.21483
ingestedAt: '2026-07-10T16:05:09.729Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/siberkampus/CVE-2025-8889'
  checkedAt: '2026-09-24T07:52:54.196Z'
exploitAvailable: true
---

## Overview

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

## Affected

- `compress_&_upload < 1.0.5`

## Remediation

Upgrade past the affected range:

- `compress_&_upload 1.0.5`
