Description
The WP3D Model Import Viewer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_import_file() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Problem types
CWE-434 Unrestricted Upload of File with Dangerous Type
Product status
* (semver)
Timeline
| 2025-12-12: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-232c-40c0-9e4b-d1cedfe52b26?source=cve
wordpress.org/plugins/wp3d-model-import-block/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.