CVE-2025-47549: WordPress BEAF plugin <= 4.6.10 - Arbitrary File Upload Vulnerability
Published May 7, 2025
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic BEAF beaf-before-and-after-gallery allows Upload a Web Shell to a Web Server.This issue affects BEAF: from n/a through <= 4.6.10.
Affected Software
3 affected components
Themefic BEAF<=4.6.10
WordPress BEAF<=4.6.10
Themefic Ultimate Before After Image Slider \& Gallery Wordpress<=4.6.10
Remediation
Information
Update the WordPress BEAF plugin to the latest available version (at least 4.6.11).
Event History
May 7, 2025
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 6, 58279
Event
via MITRE·07:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-47549?
CVE-2025-47549 has a critical severity level due to its potential to allow arbitrary file uploads, including web shells.
2
How do I fix CVE-2025-47549?
To fix CVE-2025-47549, update Themefic BEAF to version 4.6.11 or later to mitigate the vulnerability.
3
What types of files can be uploaded in CVE-2025-47549?
CVE-2025-47549 allows the upload of files with dangerous types, potentially including executable scripts and web shells.
4
Which versions of Themefic BEAF are affected by CVE-2025-47549?
CVE-2025-47549 affects Themefic BEAF versions up to and including 4.6.10.
5
What happens if I don't address CVE-2025-47549?
If CVE-2025-47549 is not addressed, attackers can exploit the vulnerability to upload malicious files, compromising your web server.