CVE-2025-47452: WordPress WP VR plugin <= 8.5.26 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR allows Upload a Web Shell to a Web Server. This issue affects WP VR: from n/a through 8.5.26.
Other sources
Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web Server.This issue affects WP VR: from n/a through <= 8.5.26.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47452?
CVE-2025-47452 is classified as a high severity vulnerability due to the potential for unrestricted file uploads leading to web shell access.
How do I fix CVE-2025-47452?
To fix CVE-2025-47452, update the RexTheme WP VR plugin to version 8.5.27 or later to mitigate the vulnerability.
Which versions of WP VR are affected by CVE-2025-47452?
CVE-2025-47452 affects all versions of RexTheme WP VR from n/a up to and including 8.5.26.
What type of attack is possible through CVE-2025-47452?
CVE-2025-47452 allows an attacker to upload dangerous file types, such as web shells, which can compromise the web server.
Is there a known exploit for CVE-2025-47452?
Yes, since CVE-2025-47452 allows file uploads without proper validation, it is a well-known vector for exploiting servers.