
🚨 CVE-2025-4391: Echo RSS Feed Post Generator <= 5... Unauthenticated file upload in WordPress plugin with zero validation = instant webshell deployment and full server compr... https://zerodaysignal.com/vulnerability/CVE-2025-4391 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces CVE-2025-4391, a WordPress plugin flaw that permits unauthenticated file uploads and can result in webshell deployment. No exploit code, patch, or evidence of active exploitation is provided.
