CVE-2025-12563: Blog2Social: Social Media Auto Post & Scheduler <= 8.6.0 - Incorrect Authorization to Video File Upload
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an incorrect capability check on theuploadVideo() function in all versions up to, and including, 8.6.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload mp4 files to the 'wp-content/uploads/<YYYY>/<MM>/' directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12563?
CVE-2025-12563 has a medium severity rating due to its potential for authenticated attackers to exploit file upload vulnerabilities.
How do I fix CVE-2025-12563?
To fix CVE-2025-12563, update the Blog2Social: Social Media Auto Post & Scheduler plugin to version 8.6.1 or later.
Who is affected by CVE-2025-12563?
CVE-2025-12563 affects all versions of the Blog2Social: Social Media Auto Post & Scheduler plugin up to and including version 8.6.0.
What types of attacks are possible with CVE-2025-12563?
CVE-2025-12563 enables authenticated attackers to upload malicious files, leading to potential further exploitation of the site.
Is CVE-2025-12563 a zero-day vulnerability?
CVE-2025-12563 is not classified as a zero-day since the vulnerability has been identified and a patch is available.