PT-2025-50316 · WordPress · Video Merchant

Ala Arfaoui

·

Published

2025-12-10

·

Updated

2025-12-15

·

CVE-2025-14390

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Video Merchant plugin for WordPress versions 5.0.4 and earlier
Description The Video Merchant plugin for WordPress is susceptible to Cross-Site Request Forgery (CSRF). This is due to inadequate nonce validation within the video merchant add video file() function. Successful exploitation allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution if they can trick a site administrator into performing an action, such as clicking a malicious link.
Recommendations Update the Video Merchant plugin to a version newer than 5.0.4.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-14390

Affected Products

Video Merchant