CVE-2025-12957: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12957 is an arbitrary file upload vulnerability in the All-in-One Video Gallery plugin for WordPress, affecting all versions up to and including 4.5.7. The flaw stems from insufficient file type validation for VTT (WebVTT subtitle) files, which allows double-extension files to bypass sanitization and be accepted as valid VTT files. It was disclosed on January 16, 2026, with the CVE record submitted by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assigned by Wordfence (Wordfence, NVD).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The plugin's VTT file validation logic fails to properly inspect the full file extension chain, allowing an attacker to craft a file with a double extension (e.g., shell.php.vtt) that passes the VTT check while retaining an executable extension. An authenticated attacker with at minimum author-level WordPress access can upload such a file through the plugin's media upload functionality. A patch was committed to the WordPress plugin repository (changeset 3405593), indicating the fix addresses the sanitization logic for VTT file type detection (Wordfence, Plugin Changeset).

Impact

Successful exploitation allows an authenticated attacker to upload arbitrary files — including web shells — to the WordPress server, potentially enabling remote code execution (RCE). This could result in full compromise of the WordPress installation, including unauthorized access to sensitive data (confidentiality), modification or defacement of site content (integrity), and disruption of service availability. Lateral movement within the hosting environment is also possible if the web server process has broad filesystem permissions (Wordfence, NVD).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.111%, indicating a low current probability of exploitation in the near term. Exploitation requires authenticated access at the author level or above, which limits opportunistic mass exploitation but remains a realistic threat in targeted or insider scenarios (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the All-in-One Video Gallery plugin (versions ≤ 4.5.7) using tools like WPScan or by inspecting plugin directories exposed via the web server.
  2. Obtain authenticated access: Log in to the WordPress site with an account that has at minimum author-level privileges (e.g., via credential stuffing, phishing, or a compromised account).
  3. Craft a double-extension payload: Create a malicious PHP web shell file named with a double extension such as webshell.php.vtt to bypass the plugin's VTT file type validation.
  4. Upload the malicious file: Use the All-in-One Video Gallery plugin's subtitle/VTT upload functionality to upload the crafted file. The insufficient validation accepts it as a valid VTT file.
  5. Locate the uploaded file: Determine the upload path (typically within wp-content/uploads/) by observing the plugin's response or by browsing predictable upload directories.
  6. Execute the payload: Access the uploaded file via its URL in a browser or HTTP client to trigger server-side PHP execution, achieving remote code execution on the server (Wordfence, Plugin Changeset).

Indicators of compromise

  • File System: Presence of files with double extensions (e.g., .php.vtt, .php5.vtt, .phtml.vtt) in WordPress upload directories (wp-content/uploads/); unexpected PHP or script files in media upload folders.
  • Logs: Web server access logs showing POST requests to All-in-One Video Gallery upload endpoints followed by GET requests to files with double extensions in the uploads directory; HTTP 200 responses to requests for .vtt-suffixed files that return PHP output.
  • Network: Outbound connections from the web server process to unknown external IPs, which may indicate post-exploitation activity such as reverse shell or data exfiltration.
  • Process: Unusual child processes spawned by the web server (e.g., apache2, nginx, php-fpm) such as bash, curl, wget, or python that are not part of normal WordPress operation.

Mitigation and workarounds

Site administrators should update the All-in-One Video Gallery plugin to a version beyond 4.5.7 that incorporates the fix committed in changeset 3405593 (Plugin Changeset). If an immediate update is not possible, consider deactivating or removing the plugin, restricting author-level access to only fully trusted users, and deploying Web Application Firewall (WAF) rules to block uploads of files with double extensions or suspicious MIME types. Additionally, monitor the wp-content/uploads/ directory for unexpected script files and review upload logs for anomalous activity (Wordfence).

Community reactions

Wordfence reported the vulnerability in their weekly WordPress vulnerability report covering January 12–18, 2026, and it was detected by Qualys application security scanners in January 2026 (Wordfence Blog, Qualys). The vulnerability received limited but notable social media attention, with mentions on Mastodon/Infosec.exchange and Bluesky from security community accounts. Overall community reaction was measured, consistent with the absence of active exploitation or a public PoC.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management