Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27570 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field in all versions up to, and including, 1.0.24. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. |
Wed, 10 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Sep 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the HdnMediaSelection_image field in all versions up to, and including, 1.0.24. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
| Title | Responsive Filterable Portfolio <= 1.0.24 - Authenticated (Admin+) Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:32:32.376Z
Reserved: 2025-09-05T18:50:44.711Z
Link: CVE-2025-10049
Updated: 2025-09-10T16:10:42.989Z
Status : Deferred
Published: 2025-09-10T07:15:43.887
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-10049
No data.
OpenCVE Enrichment
Updated: 2026-04-22T22:30:28Z
EUVD