CVE-2025-47452 is a critical unrestricted file upload vulnerability (CWE-434) affecting RexTheme WP VR plugin versions up to 8.5.26, enabling an authenticated attacker with low privileges to upload a web shell. This flaw rates a CVSS 9.9 Critical score, indicating a network-exploitable vulnerability with low complexity and complete impact on system confidentiality, integrity, and availability. Although not yet in CISA's KEV catalog, it is on an active "Hot List," signifying high concern. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has garnered minimal community discussion or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 8.5.26CPE match | cpe:2.3:a:rextheme:wp_vr:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.