PT-2025-30372 · WordPress · Foxypress

Published

2025-07-22

·

Updated

2025-12-16

·

CVE-2012-10020

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FoxyPress versions up to 0.4.2.1
Description The FoxyPress plugin for WordPress is susceptible to arbitrary file uploads due to insufficient file type validation in the uploadify.php file. This allows unauthenticated attackers to upload arbitrary files to the affected site's server, potentially enabling remote code execution.
Recommendations Update FoxyPress to a version later than 0.4.2.1.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2012-10020

Affected Products

Foxypress