CVE-2012-10019

CRITICAL

Front End Editor <2.3 - File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-10019. PoCs published by Sammy, including Metasploit module exploits/unix/webapp/wp_frontend_editor_file_upload.

AI-analyzed exploit summary This Metasploit module exploits an authenticated file upload vulnerability in the WordPress Front-end Editor plugin (CVE-2012-10019), allowing arbitrary PHP file uploads via a custom upload mechanism. The exploit uploads a PHP payload and triggers it to achieve remote code execution.

Description

The Front End Editor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload.php file in versions before 2.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Sammy · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_frontend_editor_file_upload.rb

This Metasploit module exploits an authenticated file upload vulnerability in the WordPress Front-end Editor plugin (CVE-2012-10019), allowing arbitrary PHP file uploads via a custom upload mechanism. The exploit uploads a PHP payload and triggers it to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress Front-end Editor plugin 2.2.1
Auth required
Prerequisites: Valid WordPress credentials · Front-end Editor plugin version <= 2.2.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7952
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
scribu/Front-end Editor < 2.3
scribu/front-end_editor < 2.3
Published Jul 19, 2025
Tracked Since Feb 18, 2026