CVE-2025-8889

LOW

Eliehanna Compress And Upload Plugin - Unrestricted File Upload

Title source: rule

Description

The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

Exploits (1)

nomisec WORKING POC
by siberkampus · poc
https://github.com/siberkampus/CVE-2025-8889

Scores

CVSS v3 3.8
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
eliehanna/compress_and_upload_plugin < 1.0.5
Published Sep 09, 2025
Tracked Since Feb 18, 2026