CVE-2025-3914

Published Apr 26, 2025

Last updated 3 days ago

CVSS high 8.8
WordPress
Airtable

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-3914 affects the Aeropage Sync for Airtable plugin for WordPress. It stems from a lack of file type validation in the `aeropage_media_downloader` function. This vulnerability is present in all versions up to and including 3.2.0. The absence of file type validation allows authenticated attackers with subscriber-level access or higher to upload arbitrary files to the affected server. This could potentially lead to remote code execution, thereby compromising the WordPress site.

Description
The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Source
security@wordfence.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security@wordfence.com
CWE-434

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

8