Unrated severityNVD Advisory· Published Jun 10, 2025· Updated Jun 11, 2025
Axle Demo Importer <= 1.0.3 - Author+ Arbitrary File Upload
CVE-2025-4954
Description
The Axle Demo Importer WordPress plugin through 1.0.3 does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server
Affected products
2- WordPress/Axle Demo Importerdescription
- Range: <=1.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/673f35ff-e1d5-4099-86e7-8b6e3e410ef8/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.