codecanyon.net
https://codecanyon.net/item/echo-rss-feed-post-generator-plugin-for-wordpress/19486974 CVE-2025-4391
CRITICAL
Echo RSS Feed Post Generator <= 5.4.8.1 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2025-4391 has a selected CVSS score of 9.8 (critical).
Description
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the echo_generate_featured_image() function in all versions up to, and including, 5.4.8.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 19, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Echo RSS Feed Post GeneratorBrowse CodeRevolution / Echo RSS Feed Post GeneratorDefault status: unaffected | CVE List | Through 5.4.8.1 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-4391 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/72de9f64-f3e0-4705-adc1-6c22076b382f?source=cve