
🚨 CVE-2025-2941: Drag and Drop Multiple File Uploa... Unauthenticated file move to RCE via wp-config.php relocation - trivial path traversal with zero validation makes this a... https://zerodaysignal.com/vulnerability/CVE-2025-2941 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet highlights CVE‑2025‑2941 as enabling RCE through a trivial path traversal that relocates wp-config.php, linking to a site for further details, but it does not claim active exploitation, provide patches, or disclose exploit code.
