CVE-2025-12057Active Exploitation

LOWCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-07-12: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-07-12: 1Technical Details · 2026-04-14: 104-1407-12
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post lists CVEs that attackers reportedly used against WordPress and Joomla websites, suggesting active exploitation, but it lacks concrete details or evidence of in‑the‑wild incidents.

    1301142.4K
    2.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-12057 Exploit in the wild confirmed for CVE-2025-12057 (CVSS null). The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX acti... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    Alert reports active exploitation of CVE-2025-12057 involving unauthorized AJAX actions in the WavePlayer WordPress plugin, with no PoC or patch referenced.

    00000212
    5.6K followersView on X

Explore more