CVE-2025-14938

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is due to missing authorization and capability checks on the AJAX endpoint handling file uploads. This makes it possible for unauthenticated attackers to upload arbitrary media to the site's media library, without achieving direct code execution.
Configurations

No configuration.

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) El plugin Listeo Core para WordPress es vulnerable a la carga arbitraria de medios no autenticada en todas las versiones hasta la 2.0.27, inclusive, a través de la función 'listeo_core_handle_dropped_media'. Esto se debe a la falta de comprobaciones de autorización y capacidad en el endpoint AJAX que gestiona las cargas de archivos. Esto permite a atacantes no autenticados cargar medios arbitrarios en la biblioteca de medios del sitio, sin lograr la ejecución directa de código.

04 Apr 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 12:16

Updated : 2026-07-24 22:10


NVD link : CVE-2025-14938

Mitre link : CVE-2025-14938

CVE.ORG link : CVE-2025-14938


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type