WordPress · Wp Dispatcher · CVE-2025-9212
**Name of the Vulnerable Software and Affected Versions**
WP Dispatcher plugin for WordPress versions prior to 1.2.1
**Description**
The WP Dispatcher plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation within the `wp dispatcher process upload()` function. This allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files to the server. While an .htaccess file exists to limit the ability to achieve remote code execution, the possibility remains.
**Recommendations**
Update the WP Dispatcher plugin to version 1.2.1 or later.