First published: Thu Apr 17 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in rockgod100 Theme File Duplicator allows Using Malicious Files. This issue affects Theme File Duplicator: from n/a through 1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Theme File Duplicator Plugin | <=1.3 | |
rockgod100 Theme File Duplicator | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-27282 is classified as high due to the potential for malicious file execution.
To fix CVE-2025-27282, upgrade the Theme File Duplicator plugin to the latest version, which addresses the vulnerability.
CVE-2025-27282 affects the Theme File Duplicator plugin versions up to and including 1.3.
The impact of CVE-2025-27282 allows unauthorized upload and execution of malicious files on vulnerable installations.
Yes, CVE-2025-27282 can be exploited remotely if the vulnerability is present and no mitigation measures are in place.