The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/5d84a577-62aa-4aa2-ac39-b146eae65243/ | Exploit Third Party Advisory |
Configurations
History
28 Jan 2026, 19:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:eliehanna:compress_and_upload_plugin:*:*:*:*:*:wordpress:*:* | |
| CWE | CWE-434 | |
| References | () https://wpscan.com/vulnerability/5d84a577-62aa-4aa2-ac39-b146eae65243/ - Exploit, Third Party Advisory | |
| First Time |
Eliehanna
Eliehanna compress And Upload Plugin |
13 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.8 |
09 Sep 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Sep 2025, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-09 06:15
Updated : 2026-01-30 20:38
NVD link : CVE-2025-8889
Mitre link : CVE-2025-8889
CVE.ORG link : CVE-2025-8889
JSON object : View
Products Affected
eliehanna
- compress_and_upload_plugin
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
