CVE-2025-11170: WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload
The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the CpiwmImportController::import function in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11170?
CVE-2025-11170 has a high severity rating due to the potential for arbitrary file uploads by unauthenticated attackers.
How do I fix CVE-2025-11170?
To fix CVE-2025-11170, upgrade the WP移行専用プラグイン for CPI plugin to version 1.0.3 or later.
Which versions of the WP移行専用プラグイン for CPI are affected by CVE-2025-11170?
All versions of the WP移行専用プラグイン for CPI up to and including 1.0.2 are affected by CVE-2025-11170.
What type of attack is possible due to CVE-2025-11170?
CVE-2025-11170 allows attackers to perform arbitrary file uploads, potentially leading to further exploitation of the site.
Is authentication required to exploit CVE-2025-11170?
No, CVE-2025-11170 can be exploited by unauthenticated attackers, making it more critical.