firefart.atThird-party advisory
https://firefart.at/post/turning_piwik_superuser_creds_into_rce CVE-2025-34104
CRITICAL
Piwik Authenticated RCE via Custom Plugin Upload
Record summary
CVE-2025-34104 has a selected CVSS score of 9.4 (critical); EIP currently links 1 catalogued exploit.
Description
An authenticated remote code execution vulnerability exists in Piwik (now Matomo) versions prior to 3.0.3 via the plugin upload mechanism. In vulnerable versions, an authenticated user with Superuser privileges can upload and activate a malicious plugin (ZIP archive), leading to arbitrary PHP code execution on the underlying system. Starting with version 3.0.3, plugin upload functionality is disabled by default unless explicitly enabled in the configuration file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Web Analytics PlatformBrowse Piwik (now Matomo) / Web Analytics PlatformDefault status: unaffected | CVE List | Before 3.0.3 | affected |
Proofs of concept
1Catalogued exploits
MetasploitPiwik Superuser Plugin UploadMetasploit exploitby FireFartNot analyzed1 file
References
6matomo.orgVendor advisory
https://matomo.org/changelog/piwik-3-0-3 matomo.orgproduct
https://matomo.org/faq/plugins/faq_21 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-34104 raw.githubusercontent.comexploit
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/piwik_superuser_plugin_upload.rb vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/piwik-authenticated-rce-via-custom-plugin-upload