CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2018-25335 — WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerabili...

·Source: NIST NVD

Updated:

Executive Summary

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory.

Analysis

WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the uploads directory. CVSS Score: 9.8. Published: 2026-05-17T13:16:45.220.

Indicators of Compromise (1)

CVE (1)
CVE-2018-25335
Source Attribution

Originally published by NIST NVD on May 17, 2026. Verified by: NIST.

Related Threats