Critical Vulnerabilities inWordPress: Arbitrary File Upload, Code Injection and Creating Administrator Accounts. Protect Your Sites! Recently, three vulnerabilities have been published...
Recently, three critical vulnerabilities have been published inWordPresswith CVE-2025-69129, CVE-2026-25470 and CVE-2026-8935. These vulnerabilities can have a significant impact on the security of your sites and it is essential that you fix them as soon as possible.
CVE-2025-69129: Arbitrary File Upload
The CVE-2025-69129 vulnerability affects theWordPress& WooCommerce Scraper Plugin, Import Data from Any Site, versions <= 1.0.7. This vulnerability allows an attacker to upload arbitrary files to your server without being authenticated, which can lead to malicious code execution and compromise your site’s security.
To fix this vulnerability, we recommend that you update the plugin to the latest version or disable it until an update is available.
CVE-2026-25470: Code Injection
The CVE-2026-25470 vulnerability affects the ACPT (Pro) plugin - Custom Post Types Plugin forWordPress, versions from 2.0.47. This vulnerability allows an attacker to inject malicious code into your site, which can lead to compromising security and performing unauthorized actions.
To fix this vulnerability, we recommend that you update the plugin to the latest version or disable it until an update is available.
CVE-2026-8935: Creating administrator accounts
The CVE-2026-8935 vulnerability affects the WP MAPS PROWordPressplugin, previous versions 6.1.1. This vulnerability allows an attacker to create an administrator account on your site without being logged in, which can lead to security compromise and perform unauthorized actions.
To fix this vulnerability, we recommend that you update the plugin to the latest version or disable it until an update is available.
All these vulnerabilities can have a significant impact on the security of your sites and it is essential to fix them as soon as possible. It is also important to check your sites regularly for any vulnerabilities and implement appropriate security measures, such as an anti-attack protection system (WAF), to prevent exploitation of these vulnerabilities.
If you are concerned about the security of your website, we recommend that you contact us. Zebrabyte to discuss the available protection options.