CVE-2025-12528
中文标题:
(暂无数据)
英文标题:
Pie Forms for WP <= 1.6 - Unauthenticated Arbitrary File Upload
漏洞描述
中文描述:
(暂无数据)
英文描述:
The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic function. This is due to insufficient file type validation where the validate_classic method validates file extensions and sets error messages but does not prevent the file upload process from continuing. This makes it possible for unauthenticated attackers to upload files with dangerous extensions such as PHP, which makes remote code execution possible. In order to exploit this vulnerability, the attacker needs to guess the directory in which the file is placed (which is a somewhat predictable hash). In addition to that, the file name is generated using a secure hash method, limiting the exploitability of this vulnerability.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| genetechproducts | Pie Forms — Drag & Drop Form Builder | - | ≤ 1.6 | - |
cpe:2.3:a:genetechproducts:pie_forms_—_drag_&_drop_form_builder:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-12528 |
2025-11-19 04:05:45 | 2026-01-12 02:10:40 |
| NVD | nvd_CVE-2025-12528 |
2025-11-19 04:07:44 | 2026-01-12 02:27:25 |
版本与语言
安全公告
变更历史
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']