The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Jul 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wordpress
Wordpress wordpress |
|
Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 24 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Jul 2025 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | Ebook Store <= 5.8012 - Unauthenticated Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-07-24T04:24:13.455Z
Updated: 2025-07-24T13:36:42.819Z
Reserved: 2025-07-10T16:51:50.723Z
Link: CVE-2025-7437

Updated: 2025-07-24T13:35:03.536Z

Status : Awaiting Analysis
Published: 2025-07-24T07:15:54.740
Modified: 2025-07-25T15:29:44.523
Link: CVE-2025-7437

No data.