PT-2025-40497 · WordPress · Ap Background

Kenneth Dunn

·

Published

2025-10-03

·

Updated

2025-10-08

·

CVE-2025-9561

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AP Background plugin for WordPress versions 3.8.1 through 3.8.2
Description The AP Background plugin for WordPress is susceptible to arbitrary file uploads because of missing authorization and inadequate file validation within the advParallaxBackAdminSaveSlider() handler. This allows authenticated attackers with Subscriber-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update to a version of the AP Background plugin for WordPress that addresses this issue.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-9561

Affected Products

Ap Background