Record summary

CVE-2018-25335 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Peugeot Music - Arbitrary File UploadExploitDB exploitby Mr.7zNot analyzed1 file
ExploitDB

PoC details

References

3