CVE-2019-25295

The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-08 02:15

Updated : 2026-01-08 18:08


NVD link : CVE-2019-25295

Mitre link : CVE-2019-25295

CVE.ORG link : CVE-2019-25295


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')