CVE-2025-8889: Compress Then Upload < 1.0.5 - Admin+ Arbitrary File Upload
Published Sep 9, 2025
·Updated
The Compress & Upload WordPress plugin before 1.0.5 does not properly validate uploaded files, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
Affected Software
2 affected components
WordPress Compress & Upload<1.0.5
Eliehanna Compress \& Upload Wordpress<1.0.5
Event History
Sep 9, 2025
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-8889?
CVE-2025-8889 has a high severity rating due to its potential for arbitrary file uploads.
2
How do I fix CVE-2025-8889?
To fix CVE-2025-8889, upgrade the Compress & Upload plugin to version 1.0.5 or later.
3
Who is affected by CVE-2025-8889?
CVE-2025-8889 affects high privilege users, particularly admins in multisite WordPress setups.
4
What types of files can be uploaded due to CVE-2025-8889?
CVE-2025-8889 allows the upload of arbitrary files, which could include potentially malicious files.
5
Is CVE-2025-8889 exploitable on all WordPress installations?
CVE-2025-8889 is primarily exploitable on installations using the Compress & Upload plugin version prior to 1.0.5.