The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 18 Jun 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Pixabay Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pixabay_upload function in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | Pixabay Images <= 3.4 - Authenticated (Author+) Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-06-18T02:21:37.425Z
Updated: 2025-06-18T14:57:43.040Z
Reserved: 2025-05-07T10:18:02.747Z
Link: CVE-2025-4413

Updated: 2025-06-18T14:57:39.430Z

Status : Awaiting Analysis
Published: 2025-06-18T03:15:25.560
Modified: 2025-06-18T13:46:52.973
Link: CVE-2025-4413

No data.