---
id: CVE-2025-9212
title: >-
  The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads
  due to missing file type validation in the wp_dispatcher_process_upload()
  function in all versions up to, and including, 1.2.0
summary: >-
  The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads
  due to missing file type validation in the wp_dispatcher_process_upload()
  function in all versions up to, and including, 1.2.0. This makes it possible
  for aut…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-03'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9212'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-dispatcher/trunk/admin/class-wp-dispatcher-add-new-upload.php#L110
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/f0b9c46d-72db-43f3-b17b-0747375d45c9?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00511
epssPercentile: 0.417
ingestedAt: '2026-10-08T22:11:53.767Z'
---

## Overview

The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The directory does have an .htaccess file which limits the ability to achieve remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
