PT-2025-30124 · WordPress · Front End Editor

Published

2025-07-19

·

Updated

2025-12-19

·

CVE-2012-10019

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Front End Editor plugin for WordPress versions prior to 2.3
Description The Front End Editor plugin for WordPress is susceptible to arbitrary file uploads due to missing file type validation via the upload.php file. This allows unauthenticated attackers to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update the Front End Editor plugin to version 2.3 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2012-10019

Affected Products

Front End Editor