CVE-2025-9314: Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload
Published Sep 2, 2026
·Updated
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
Affected Software
2 affected components
WordPress Developer Tools<=1.1.3
SWFUpload
Event History
Sep 2, 2026
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using the Developer Tools plugin version 1.1.3 or earlier are affected. The vulnerable functionality is in the plugin’s bundled SWFUpload component.
2
Does exploitation require an account or user interaction?
No. The vulnerability is unauthenticated and has network attack vector, so an attacker does not need WordPress credentials or user interaction to attempt exploitation.
3
What could an attacker achieve?
An attacker may upload arbitrary files. The reported impact includes high confidentiality, integrity, and availability impact.