CVE-2025-30580

Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote Code Inclusion.This issue affects DigiWidgets Image Editor: from n/a through <= 1.10.
Configurations

No configuration.

History

23 Apr 2026, 15:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 10.0

01 Apr 2026, 17:20

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de control inadecuado de la generación de código ('Inyección de código') en NotFound DigiWidgets Image Editor permite la inclusión remota de código. Este problema afecta al editor de imágenes DigiWidgets desde n/d hasta la versión 1.10.
Summary (en) Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10. (en) Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidgets-image-editor allows Remote Code Inclusion.This issue affects DigiWidgets Image Editor: from n/a through <= 1.10.
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : unknown
References
  • {'url': 'https://patchstack.com/database/wordpress/plugin/digiwidgets-image-editor/vulnerability/wordpress-digiwidgets-image-editor-1-10-remote-code-execution-rce-vulnerability?_s_id=cve', 'source': 'audit@patchstack.com'}
  • () https://patchstack.com/database/Wordpress/Plugin/digiwidgets-image-editor/vulnerability/wordpress-digiwidgets-image-editor-1-10-remote-code-execution-rce-vulnerability?_s_id=cve -

01 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-01 21:15

Updated : 2026-06-17 09:08


NVD link : CVE-2025-30580

Mitre link : CVE-2025-30580

CVE.ORG link : CVE-2025-30580


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')