Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-3054-Exploit | Kitploit
Tools/GitHubGitHub/frogchung/cve-2025-3054-exploit
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubfrogchung/cve-2025-3054-exploit

CVE-2025-3054-Exploit

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-3054

Exploit:

Download here

Details

  • CVE ID: CVE-2025-3054
  • Published: June 5, 2025
  • CVSS: 8.8
  • Patch Available: (No official patch yet)

Impact

The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Please note that this requires the 'Private Message' module to be enabled and the Business version of the PRO software to be in use.

Contact

For inquiries, please contact:[email protected]

Download Tool