First published: Tue Apr 15 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in EPC AI Hub allows Upload a Web Shell to a Web Server. This issue affects AI Hub: from n/a through 1.3.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
EPC AI Hub | >=1.3.3 | |
WordPress AI Hub | <=1.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26927 has a critical severity rating due to its potential to allow unrestricted file uploads leading to web shell deployment.
To address CVE-2025-26927, update the EPC AI Hub to version 1.3.4 or higher, or apply relevant security patches if available.
CVE-2025-26927 primarily affects systems by allowing the upload of files with dangerous types, such as web shells.
CVE-2025-26927 affects EPC AI Hub versions from n/a through 1.3.3 and the WordPress AI Hub plugin up to version 1.3.3.
The potential consequences of CVE-2025-26927 include unauthorized access to the web server and the ability to execute malicious code.