First published: Thu Apr 17 2025(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw allows Using Malicious Files. This issue affects I Draw: from n/a through 1.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
aidraw | <=1.0 | |
WordPress | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39436 has a high severity rating due to its potential for exploitation through unrestricted file uploads.
To fix CVE-2025-39436, update the I Draw plugin to the latest version that addresses this vulnerability.
CVE-2025-39436 allows the upload of any file type, including potentially malicious ones, due to unrestricted file upload capabilities.
The vulnerability CVE-2025-39436 affects all versions of I Draw up to and including 1.0.
The potential impacts of CVE-2025-39436 include unauthorized access and execution of malicious code on the server.