CVE-2025-3914

Published Apr 26, 2025

Last updated 2 months ago

CVSS high 8.8
WordPress
Airtable

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-3914 affects the Aeropage Sync for Airtable plugin for WordPress. It stems from a lack of file type validation in the `aeropage_media_downloader` function. This vulnerability is present in all versions up to and including 3.2.0. The absence of file type validation allows authenticated attackers with subscriber-level access or higher to upload arbitrary files to the affected server. This could potentially lead to remote code execution, thereby compromising the WordPress site.

Description
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source
security@wordfence.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@wordfence.com
CWE-434
nvd@nist.gov
CWE-434

Social media

Hype score
Not currently trending

Configurations