The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Thu, 08 Jan 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site. | |
| Title | WP Cost Estimation < 9.660 - Upload Directory Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-08T16:25:07.777Z
Reserved: 2026-01-07T13:49:54.277Z
Link: CVE-2019-25295
Updated: 2026-01-08T16:25:03.939Z
Status : Awaiting Analysis
Published: 2026-01-08T02:15:52.447
Modified: 2026-01-08T18:08:18.457
Link: CVE-2019-25295
No data.
OpenCVE Enrichment
Updated: 2026-01-08T09:47:45Z