PT-2025-19761 · WordPress · External Image Replace Plugin

István Márton

·

Published

2025-05-05

·

Updated

2025-05-06

·

CVE-2025-4279

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions External image replace plugin for WordPress versions up to, and including, 1.0.8
Description The issue is related to missing file type validation in the external image replace get posts::replace post function, allowing authenticated attackers with contributor-level and above permissions to upload arbitrary files on the affected site's server. This could potentially lead to remote code execution.
Recommendations For versions up to, and including, 1.0.8, consider disabling the external image replace get posts::replace post function until a patch is available to prevent arbitrary file uploads. Restrict access to file upload functionality for users with contributor-level and above permissions to minimize the risk of exploitation.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-4279

Affected Products

External Image Replace Plugin