StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
97Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 9.8epss 39%
de la publicación al arma10 días
Publicada en NVD16 ago
1ª PoC+10d
metasploit4 ago
VulnCheck15 ago
probabilidad de explotación
39%top 1% de las CVE
explotación observada
síVulnCheck
5 exploit(s) público(s)
The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the /wp-json/storychief/webhook REST-API endpoint that does not have sufficient filetype validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
storychief · StoryChiefPoCs públicas encontradas — 5
exploitdbwww.exploit-db.com/exploits/52422no verificadogithubgithub.com/AnotherSec/CVE-2025-7441★ 3githubgithub.com/Nxploited/CVE-2025-7441★ 0vulncheckvulncheck.com/xdb/a9c6acda0c3ano verificadovulncheckvulncheck.com/xdb/83834bac8299no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.