PT-2025-13604 · WordPress · Inline Image Upload For Bbpress

Muhammad Yudha

·

Published

2025-03-29

·

Updated

2025-04-03

·

CVE-2025-2006

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Inline Image Upload for BBPress plugin for WordPress versions up to, and including, 1.1.19
Description The issue is related to missing file type validation in the file uploading functionality, allowing authenticated attackers with Subscriber-level access and above to upload arbitrary files on the affected site's server. This could potentially lead to remote code execution. In certain configurations, where the "Allow guest users without accounts to create topics and replies" setting is enabled, unauthenticated attackers may also exploit this issue.
Recommendations For versions up to, and including, 1.1.19, update to a version that includes the necessary file type validation to prevent arbitrary file uploads. As a temporary workaround, consider disabling the file uploading functionality until a patch is available. Restrict access to the file uploading feature to minimize the risk of exploitation, especially when the "Allow guest users without accounts to create topics and replies" setting is enabled.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-2006

Affected Products

Inline Image Upload For Bbpress