Skip to main content

CVE-2025-58819: CWE-434 Unrestricted Upload of File with Dangerous Type in CreedAlly Bulk Featured Image

Critical
VulnerabilityCVE-2025-58819cvecve-2025-58819cwe-434
Published: Fri Sep 05 2025 (09/05/2025, 13:45:18 UTC)
Source: CVE Database V5
Vendor/Project: CreedAlly
Product: Bulk Featured Image

Description

Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image allows Upload a Web Shell to a Web Server. This issue affects Bulk Featured Image: from n/a through 1.2.2.

Technical Details

Data Version
5.1
Assigner Short Name
Patchstack
Date Reserved
2025-09-05T10:49:25.892Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68baeaa357c5b37b67a46069

Added to database: 9/5/2025, 1:50:27 PM

Last updated: 9/5/2025, 1:50:27 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats