CVE-2025-34083: WordPress AIT CSV Import/Export Plugin ≤ 3.0.3 Unauthenticated RCE
Published Jul 9, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2020-36849.
Affected Software
1 affected component
WordPress AIT CSV Import/Export<=3.0.3
Event History
Jul 9, 2025
CVE Published
via MITRE·12:50 AM
Rejected
via MITRE·12:50 AM
Data Sourced
via NVD·01:15 AM
Description
Jul 16, 2025
Rejected
via MITRE·03:49 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-34083?
CVE-2025-34083 is considered a high severity vulnerability due to its potential for arbitrary file uploads without authentication.
2
How do I fix CVE-2025-34083?
To mitigate CVE-2025-34083, update the WordPress AIT CSV Import/Export plugin to a version higher than 3.0.3.
3
What versions of the AIT CSV Import/Export plugin are affected by CVE-2025-34083?
CVE-2025-34083 affects the AIT CSV Import/Export plugin versions up to and including 3.0.3.
4
What type of vulnerability is CVE-2025-34083?
CVE-2025-34083 is classified as an unrestricted file upload vulnerability.
5
Is authentication enforced in the vulnerable endpoint related to CVE-2025-34083?
No, the upload handler at upload-handler.php does not enforce authentication, allowing unauthenticated arbitrary file uploads.