Skip to main content
Back to Blog
20 June 2026, byZebrabyte Breaches and incidents

Critical Vulnerabilities inWordPress- CVE-2025-69129, CVE-2026-25470, CVE-2026-8935

Critical Vulnerabilities inWordPress- CVE-2025-69129, CVE-2026-25470, CVE-2026-8935

Critical Vulnerabilities inWordPress: Arbitrary File Upload, Code Injection and Creating Administrator Accounts. Protect Your Sites! Recently, three vulnerabilities have been published...

Recently, three critical vulnerabilities have been published inWordPresswith CVE-2025-69129, CVE-2026-25470 and CVE-2026-8935. These vulnerabilities can have a significant impact on the security of your sites and it is essential that you fix them as soon as possible.

CVE-2025-69129: Arbitrary File Upload

The CVE-2025-69129 vulnerability affects theWordPress& WooCommerce Scraper Plugin, Import Data from Any Site, versions <= 1.0.7. This vulnerability allows an attacker to upload arbitrary files to your server without being authenticated, which can lead to malicious code execution and compromise your site’s security.

To fix this vulnerability, we recommend that you update the plugin to the latest version or disable it until an update is available.

CVE-2026-25470: Code Injection

The CVE-2026-25470 vulnerability affects the ACPT (Pro) plugin - Custom Post Types Plugin forWordPress, versions from 2.0.47. This vulnerability allows an attacker to inject malicious code into your site, which can lead to compromising security and performing unauthorized actions.

To fix this vulnerability, we recommend that you update the plugin to the latest version or disable it until an update is available.

CVE-2026-8935: Creating administrator accounts

The CVE-2026-8935 vulnerability affects the WP MAPS PROWordPressplugin, previous versions 6.1.1. This vulnerability allows an attacker to create an administrator account on your site without being logged in, which can lead to security compromise and perform unauthorized actions.

To fix this vulnerability, we recommend that you update the plugin to the latest version or disable it until an update is available.

All these vulnerabilities can have a significant impact on the security of your sites and it is essential to fix them as soon as possible. It is also important to check your sites regularly for any vulnerabilities and implement appropriate security measures, such as an anti-attack protection system (WAF), to prevent exploitation of these vulnerabilities.

If you are concerned about the security of your website, we recommend that you contact us. Zebrabyte to discuss the available protection options.


Scris de Zebrabyte

ZebraByteeditorial material on digital security, infrastructure, privacy and compliance, kept in the company's technical archive.

ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert