CVE-2025-3123
CVSS 3.1 Score 4.7 of 10 (medium)
Details
Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 434
CWE ID 284
Summary
CVE-2025-3123 is a critical vulnerability affecting WonderCMS 3.5.0. The issue lies in the installUpdateModuleAction function of the Theme Installation/Plugin Installation component, allowing for unrestricted uploads. This vulnerability can be exploited remotely, and the exploit has been made public. However, the real existence of this vulnerability is currently under debate. The vendor advises caution against installing themes or plugins from untrusted sources.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WonderCMS
Affected Vendors
- Wondercms