CVE-2025-0357: WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'WPBProfilecontroller::handleimageupload' function in versions up to, and including, 1.6.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0357?
CVE-2025-0357 has a high severity due to its potential for arbitrary file uploads by unauthenticated attackers.
How do I fix CVE-2025-0357?
To fix CVE-2025-0357, update the WPBookit plugin to version 1.7.0 or higher, which addresses the insufficient file type validation issue.
Which versions of WPBookit are affected by CVE-2025-0357?
CVE-2025-0357 affects WPBookit versions up to and including 1.6.9.
Can CVE-2025-0357 be exploited remotely?
Yes, CVE-2025-0357 can be exploited remotely by unauthenticated attackers to upload arbitrary files.
What kind of attacks can CVE-2025-0357 facilitate?
CVE-2025-0357 can facilitate various attacks including web shell uploads and malware injection due to arbitrary file upload capabilities.