Axle Demo Importer WordPress Plugin Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability exists in the Axle Demo Importer WordPress plugin, versions through 1.0.3, due to insufficient validation of uploaded files. This flaw could enable authenticated users with author privileges or higher to upload arbitrary files, including PHP scripts, to the server.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, potentially allowing for the execution of malicious scripts on the server.

Added: Jun 10, 2025, 6:16 AM
Updated: Jun 10, 2025, 6:16 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.