The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Aug 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Berqier
Berqier berqwp Wordpress Wordpress wordpress |
|
Vendors & Products |
Berqier
Berqier berqwp Wordpress Wordpress wordpress |
Fri, 01 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | |
Title | BerqWP <= 2.2.42 - Unauthenticated Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-08-01T04:24:29.246Z
Updated: 2025-08-01T13:30:00.478Z
Reserved: 2025-07-10T19:41:10.890Z
Link: CVE-2025-7443

Updated: 2025-08-01T13:29:32.784Z

Status : Awaiting Analysis
Published: 2025-08-01T05:15:36.743
Modified: 2025-08-04T15:06:15.833
Link: CVE-2025-7443

No data.