PT-2025-40491 · WordPress · Wp Dispatcher

Craig Webb

·

Published

2025-10-03

·

Updated

2025-10-08

·

CVE-2025-9212

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Dispatcher plugin for WordPress versions prior to 1.2.1
Description The WP Dispatcher plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation within the wp dispatcher process upload() function. This allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files to the server. While an .htaccess file exists to limit the ability to achieve remote code execution, the possibility remains.
Recommendations Update the WP Dispatcher plugin to version 1.2.1 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9212

Affected Products

Wp Dispatcher