First published: Tue Feb 18 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified allows Using Malicious Files. This issue affects Simplified: from n/a through 1.0.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
kodeshpa Simplified | >n/a<=1.0.6 | |
WordPress Simplified Plugin | <=1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22654 is a high severity vulnerability that allows unrestricted file uploads in kodeshpa Simplified.
To fix CVE-2025-22654, update kodeshpa Simplified to version 1.0.7 or later.
The impact of CVE-2025-22654 is that it enables attackers to upload malicious files, potentially compromising server security.
CVE-2025-22654 affects kodeshpa Simplified from version n/a up to and including version 1.0.6.
Users running kodeshpa Simplified or the WordPress Simplified Plugin version 1.0.6 or earlier are at risk from CVE-2025-22654.