CVE-2025-10690: Goza - Nonprofit Charity WordPress Theme <= 3.2.2 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation
The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads due to a missing capability check on the 'beplusimportpackinstallplugin' function in all versions up to, and including, 3.2.2. This makes it possible for unauthenticated attackers to upload zip files containing webshells disguised as plugins from remote locations to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10690?
CVE-2025-10690 has been classified as a high severity vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2025-10690?
To fix CVE-2025-10690, update the Goza Nonprofit Charity WordPress Theme to version 3.2.3 or later.
What does CVE-2025-10690 affect?
CVE-2025-10690 affects all versions of the Goza Nonprofit Charity WordPress Theme up to and including version 3.2.2.
What type of vulnerability is CVE-2025-10690?
CVE-2025-10690 is a vulnerability that allows for unauthorized arbitrary file uploads due to a missing capability check.
How can I verify if I am affected by CVE-2025-10690?
You can verify if you are affected by CVE-2025-10690 by checking the version of the Goza Nonprofit Charity WordPress Theme installed on your site.