PT-2025-14912 · Niteothemes · Niteothemes Cmp – Coming Soon & Maintenance

Savphill

·

Published

2025-04-04

·

Updated

2025-04-07

·

CVE-2025-32118

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NiteoThemes CMP – Coming Soon & Maintenance versions through 4.1.13
Description The issue is related to an Unrestricted Upload of File with Dangerous Type, allowing the use of malicious files. This can potentially lead to remote code execution (RCE) exploits.
Recommendations For versions through 4.1.13, update to a version later than 4.1.13 to resolve the issue. As a temporary workaround, consider restricting file uploads to only necessary and safe file types until a patch is available. Avoid using the plugin until the issue is resolved, to minimize the risk of exploitation.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32118

Affected Products

Niteothemes Cmp – Coming Soon & Maintenance