First published: Thu Apr 17 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra allows Using Malicious Files. This issue affects Solace Extra: from n/a through 1.3.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Solace Extra | <=1.3.1 | |
Solace Extra | <=1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32652 is classified as a medium severity vulnerability due to its potential for exploiting unrestricted file uploads.
To fix CVE-2025-32652, update Solace Extra to version 1.3.2 or later, which addresses the file upload restrictions.
CVE-2025-32652 allows attackers to upload malicious files, potentially leading to remote code execution on the affected system.
CVE-2025-32652 affects Solace Extra versions up to and including 1.3.1.
Yes, CVE-2025-32652 is applicable to the Solace Extra plugin for WordPress as well.