PT-2025-47260 · WordPress · Wp Dropzone

Kenneth Dunn

·

Published

2025-11-18

·

Updated

2025-11-23

·

CVE-2025-12775

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Dropzone versions prior to 1.1.1
Description The WP Dropzone plugin for WordPress is susceptible to unauthorized file uploads. Authenticated attackers with subscriber-level access or higher can upload arbitrary files to the server through the ajax upload handle function. This is due to a flaw in the chunked upload functionality, which writes files to the uploads directory without proper file type validation. Successful exploitation may lead to remote code execution.
Recommendations Update WP Dropzone to version 1.1.1 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12775

Affected Products

Wp Dropzone