CVE-2025-47550: WordPress Instantio plugin <= 3.3.16 - Arbitrary File Upload Vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Instantio instantio allows Upload a Web Shell to a Web Server.This issue affects Instantio: from n/a through <= 3.3.16.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47550?
CVE-2025-47550 is classified as a critical vulnerability due to its potential for unrestricted file uploads leading to web shell execution.
How do I fix CVE-2025-47550?
To fix CVE-2025-47550, upgrade Themefic Instantio to version 3.3.17 or later, which addresses this vulnerability.
What are the potential impacts of CVE-2025-47550?
The impacts of CVE-2025-47550 include unauthorized access to the server, data breaches, and malicious site redirection.
Which versions of Themefic Instantio are affected by CVE-2025-47550?
CVE-2025-47550 affects all versions of Themefic Instantio from an unspecified version up to and including 3.3.16.
Is user input validation a concern in CVE-2025-47550?
Yes, the lack of user input validation in file uploads is a key factor contributing to the vulnerability identified in CVE-2025-47550.