CVE-2025-58963: WordPress Medcity theme < 1.1.9 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in 7oroof Medcity medcity allows Upload a Web Shell to a Web Server.This issue affects Medcity: from n/a through < 1.1.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58963?
CVE-2025-58963 is considered a high severity vulnerability due to its potential to allow the upload of malicious web shells.
How do I fix CVE-2025-58963?
To fix CVE-2025-58963, update 7oroof Medcity to version 1.1.9 or later, or implement file type restrictions if immediate updates are not possible.
What is CVE-2025-58963?
CVE-2025-58963 is a vulnerability that allows unsecured file uploads, enabling attackers to upload dangerous file types such as web shells.
Which versions are affected by CVE-2025-58963?
CVE-2025-58963 affects versions of 7oroof Medcity and WordPress Medcity theme prior to 1.1.9.
Can CVE-2025-58963 be exploited remotely?
Yes, CVE-2025-58963 can be exploited remotely by attackers if file upload security measures are not in place.