CVE-2025-12973
HIGHS2B AI Assistant for WordPress - Arbitrary File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-12973. PoCs published by d0n601.
AI-analyzed exploit summary This PoC exploits an authenticated arbitrary file upload vulnerability in the S2B AI Assistant WordPress plugin (versions <= 1.7.7), allowing users with Editor+ privileges to upload a malicious PHP shell via a flawed file extension whitelist check.
Description
The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeFile() function in all versions up to, and including, 1.7.8. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Exploits (1)
This PoC exploits an authenticated arbitrary file upload vulnerability in the S2B AI Assistant WordPress plugin (versions <= 1.7.7), allowing users with Editor+ privileges to upload a malicious PHP shell via a flawed file extension whitelist check.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H