WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.
References
Configurations
No configuration.
History
17 May 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-17 13:16
Updated : 2026-05-18 17:05
NVD link : CVE-2018-25335
Mitre link : CVE-2018-25335
CVE.ORG link : CVE-2018-25335
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
