Description
Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Using Malicious Files.This issue affects SUMO Affiliates Pro: from n/a through < 11.1.0.
Published: 2025-06-09
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An arbitrary file upload flaw allows an attacker to place a file on the server without any validation of its type, creating the potential to execute malicious code or compromise the system. The vulnerability is classified as CWE-434, indicating that the upload mechanism does not enforce restrictions on file content. If a malicious file is uploaded and later accessed, the attacker could gain unauthorized control over the WordPress site or exfiltrate data.

Affected Systems

The flaw targets the FantasticPlugins SUMO Affiliates Pro WordPress plugin for versions earlier than 11.1.0. Any installation of the plugin on a WordPress site that has not applied the update is potentially exposed.

Risk and Exploitability

The CVSS score of 10 reflects a high severity with full exploitability. Although the EPSS score is below 1%, indicating a low yet non-zero probability of exploitation, the vulnerability has not been listed in the CISA KEV catalog. Attackers can exploit the flaw by uploading a crafted file through the plugin’s interface, which then becomes accessible to the web server and may execute on demand. The lack of file type validation is a clear prerequisite for exploitation, suggesting that a remote attacker with sufficient access to the plugin’s upload functionality can gain full control of the affected site.

Generated by OpenCVE AI on April 30, 2026 at 17:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest plugin version (11.1.0 or newer).
  • If an update is not immediately possible, block or restrict the upload functionality until the issue is addressed.
  • Configure the server to reject or quarantine uploaded files that are not of approved MIME types and ensure that uploaded files are stored outside the web root when possible.

Generated by OpenCVE AI on April 30, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17476 Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0. Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Using Malicious Files.This issue affects SUMO Affiliates Pro: from n/a through < 11.1.0.
Title WordPress SUMO Affiliates Pro <= 10.7.0 - Arbitrary File Upload Vulnerability WordPress SUMO Affiliates Pro plugin < 11.1.0 - Arbitrary File Upload vulnerability
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00056}

epss

{'score': 0.00061}


Mon, 09 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0.
Title WordPress SUMO Affiliates Pro <= 10.7.0 - Arbitrary File Upload Vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Fantasticplugins Sumo Affiliates Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:20.999Z

Reserved: 2025-04-04T10:02:38.419Z

Link: CVE-2025-32291

cve-icon Vulnrichment

Updated: 2025-06-09T16:02:00.906Z

cve-icon NVD

Status : Deferred

Published: 2025-06-09T16:15:39.480

Modified: 2026-04-23T15:28:54.707

Link: CVE-2025-32291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:00:14Z

Weaknesses