CyberRota Analysis
AI-GeneratedThe Developer Tools plugin for WordPress, up to version 1.1.3, is vulnerable to an unauthenticated arbitrary file upload flaw due to a weakness in the bundled SWFUpload component. This critical vulnerability could allow attackers to upload malicious files, potentially leading to remote code execution and full site compromise. WordPress site administrators and developers using this plugin should prioritize immediate updates or mitigations to safeguard their systems.
CVE
CVE-2025-9314
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%
WordPress
Original NVD Description
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component