CVE-2014-125104 describes a critical unrestricted file upload vulnerability in the VaultPress Plugin up to version 1.6.0 for WordPress, specifically within the protect_aioseo_ajax function of the class.vaultpress-hotfixes.php file when interacting with the MailPoet Plugin. This vulnerability allows remote attackers to upload arbitrary files, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS v3.1 score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low attack complexity, and lack of required privileges or user interaction. Despite its criticality, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Organizations using affected versions are strongly advised to upgrade to VaultPress Plugin 1.6.1 immediately to apply the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.1CPE matchmatch criteria | cpe:2.3:a:automattic:vaultpress:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.