PT-2025-24617 · WordPress · Axle Demo Importer

Khaled Alenazi

·

Published

2025-06-10

·

Updated

2025-06-25

·

CVE-2025-4954

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Axle Demo Importer version 1.0.3
Description The Axle Demo Importer WordPress plugin does not validate files to be uploaded, which could allow authenticated users (author and above) to upload arbitrary files such as PHP on the server.
Recommendations For version 1.0.3, consider disabling file upload functionality until a patch is available. Restrict access to the file upload feature to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-4954

Affected Products

Axle Demo Importer