Junglewise Threat Intelligence

CVE-2025-8889: Elie Hanna Compress & Upload arbitrary file upload in REST API

CVE-2025-8889 · Severity: low · CVSS 3.8 · Published 2025-09-09

Executive brief

The Compress & Upload plugin for WordPress, which is used to optimize and manage image uploads, contains a security flaw that allows high-privileged users (such as administrators) to upload unauthorized files to the server. In certain environments, like WordPress Multisite, this could allow a site administrator to bypass security restrictions and execute malicious code on the underlying server. This could lead to a full compromise of the website and its data.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the Compress & Upload plugin (formerly Compress Then Upload) before version 1.0.5. The plugin's upload interface, specifically the REST API endpoint `/wpctu-api/v1/upload`, fails to adequately validate file extensions and content. An authenticated attacker with high privileges (Administrator) can bypass weak MIME-type and header checks by intercepting the upload request, renaming the file to a .php extension, and prepending image magic bytes (e.g., GIF89a) to the payload. This allows for the execution of arbitrary PHP code on the server. While typically administrators have broad permissions, this vulnerability is significant in Multisite configurations where such uploads should be restricted.

Affected products

  • Elie Hanna Compress & Upload (Compress Then Upload) < 1.0.5

Timeline

  • 2025-08-19: disclosed: Initial public disclosure by WPScan
  • 2025-09-09: advisory: NVD publication date
  • 1.0.5: patched

References