---
id: CVE-2025-9561
title: >-
  The AP Background plugin for WordPress is vulnerable to arbitrary file uploads
  due to missing authorization and insufficient file validation within the
  advParallaxBackAdminSaveSlider() handler in versions 3.8.1 to 3.8.2
summary: >-
  The AP Background plugin for WordPress is vulnerable to arbitrary file uploads
  due to missing authorization and insufficient file validation within the
  advParallaxBackAdminSaveSlider() handler in versions 3.8.1 to 3.8.2. This
  makes it po…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-03'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9561'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/ap-background/tags/3.8.2/includes/functions.admin.php
    label: security@wordfence.com
  - url: 'https://wordpress.org/plugins/ap-background/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/e4045a2b-2bbc-4335-b6d2-af7a046f1f92?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00631
epssPercentile: 0.48601
ingestedAt: '2026-10-08T22:11:53.769Z'
---

## Overview

The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insufficient file validation within the advParallaxBackAdminSaveSlider() handler in versions 3.8.1 to 3.8.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
