← Back to browse · API

CVE-2025-3914

Severity
HIGH
CVSS
8.8
EPSS
0.14779
Risk score
40.37
CISA KEV
No
PoC
No
Published
2025-04-26
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2025-12489, GHSA-XF25-83CP-2Q6V
Products
aeropage:Aeropage Sync for Airtable 0 ≤3.2.0
Sources
euvd EUVD-2025-12489

Description

The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aeropage_media_downloader' function in all versions up to, and including, 3.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

References