
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12957 is an arbitrary file upload vulnerability in the All-in-One Video Gallery plugin for WordPress, affecting all versions up to and including 4.5.7. The flaw stems from insufficient file type validation for VTT (WebVTT subtitle) files, which allows double-extension files to bypass sanitization and be accepted as valid VTT files. It was disclosed on January 16, 2026, with the CVE record submitted by Wordfence. The vulnerability carries a CVSS v3.1 base score of 8.8 (High), assigned by Wordfence (Wordfence, NVD).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The plugin's VTT file validation logic fails to properly inspect the full file extension chain, allowing an attacker to craft a file with a double extension (e.g., shell.php.vtt) that passes the VTT check while retaining an executable extension. An authenticated attacker with at minimum author-level WordPress access can upload such a file through the plugin's media upload functionality. A patch was committed to the WordPress plugin repository (changeset 3405593), indicating the fix addresses the sanitization logic for VTT file type detection (Wordfence, Plugin Changeset).
Successful exploitation allows an authenticated attacker to upload arbitrary files — including web shells — to the WordPress server, potentially enabling remote code execution (RCE). This could result in full compromise of the WordPress installation, including unauthorized access to sensitive data (confidentiality), modification or defacement of site content (integrity), and disruption of service availability. Lateral movement within the hosting environment is also possible if the web server process has broad filesystem permissions (Wordfence, NVD).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.111%, indicating a low current probability of exploitation in the near term. Exploitation requires authenticated access at the author level or above, which limits opportunistic mass exploitation but remains a realistic threat in targeted or insider scenarios (Wordfence).
webshell.php.vtt to bypass the plugin's VTT file type validation.wp-content/uploads/) by observing the plugin's response or by browsing predictable upload directories..php.vtt, .php5.vtt, .phtml.vtt) in WordPress upload directories (wp-content/uploads/); unexpected PHP or script files in media upload folders..vtt-suffixed files that return PHP output.apache2, nginx, php-fpm) such as bash, curl, wget, or python that are not part of normal WordPress operation.Site administrators should update the All-in-One Video Gallery plugin to a version beyond 4.5.7 that incorporates the fix committed in changeset 3405593 (Plugin Changeset). If an immediate update is not possible, consider deactivating or removing the plugin, restricting author-level access to only fully trusted users, and deploying Web Application Firewall (WAF) rules to block uploads of files with double extensions or suspicious MIME types. Additionally, monitor the wp-content/uploads/ directory for unexpected script files and review upload logs for anomalous activity (Wordfence).
Wordfence reported the vulnerability in their weekly WordPress vulnerability report covering January 12–18, 2026, and it was detected by Qualys application security scanners in January 2026 (Wordfence Blog, Qualys). The vulnerability received limited but notable social media attention, with mentions on Mastodon/Infosec.exchange and Bluesky from security community accounts. Overall community reaction was measured, consistent with the absence of active exploitation or a public PoC.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."