PT-2025-35899 · WordPress · Make Connector

Ryan Kozak

·

Published

2025-09-04

·

Updated

2025-12-22

·

CVE-2025-6085

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Make Connector versions prior to 1.5.11
Description The Make Connector plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation within the upload media function. This allows authenticated attackers with Administrator-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update Make Connector to version 1.5.11 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-6085

Affected Products

Make Connector