The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Berqier Berqier berqwp Wordpress Wordpress wordpress | |
| Vendors & Products | Berqier Berqier berqwp Wordpress Wordpress wordpress | 
Fri, 01 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 01 Aug 2025 04:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
| Title | BerqWP <= 2.2.42 - Unauthenticated Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-01T04:24:29.246Z
Updated: 2025-08-01T13:30:00.478Z
Reserved: 2025-07-10T19:41:10.890Z
Link: CVE-2025-7443
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-01T13:29:32.784Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-01T05:15:36.743
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-7443
 Redhat
                        Redhat
                    No data.