CVE-2025-0394

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 434

Summary

CVE-2025-0394 is a vulnerability affecting the Groundhogg plugin, an award-winning CRM, email, and marketing automation tool for WordPress. The issue stems from missing file type validation within the gh\_big\_file\_upload() function, which is present in all versions up to and including 3.7.3.5. This vulnerability allows authenticated attackers, with Author-level access or higher, to upload arbitrary files onto the affected site's server. Successful exploitation could potentially lead to remote code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share