PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-25335 Unknown Vendor CVE debrief

CVE-2018-25335 describes a critical arbitrary file upload vulnerability in the Peugeot Music 1.0 WordPress plugin. The issue is reachable without authentication through the upload.php endpoint, where an attacker can manipulate the name parameter to upload files with arbitrary extensions. Because uploaded content can be executed from the uploads directory, this creates a direct path to remote code execution risk on affected sites.

Vendor
Unknown Vendor
Product
Unknown
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-17
Original CVE updated
2026-05-18
Advisory published
2026-05-17
Advisory updated
2026-05-18

Who should care

WordPress administrators, site owners, managed hosting providers, and security teams responsible for plugins installed on public-facing WordPress instances should prioritize this issue. It is especially relevant where Peugeot Music 1.0 may still be deployed, even if only on a small number of sites.

Technical summary

The supplied NVD-derived description identifies an unauthenticated POST-based file upload flaw in Peugeot Music 1.0. The vulnerable behavior centers on upload.php and allows attackers to influence the uploaded filename/extension through the name parameter. The source metadata also maps the issue to CWE-306 and includes references to an Exploit-DB disclosure and a VulnCheck advisory.

Defensive priority

Critical

Recommended defensive actions

  • Identify whether Peugeot Music 1.0 is installed on any WordPress environment you manage.
  • Remove or disable the Peugeot Music plugin if it is not strictly required.
  • If the plugin must remain in place, restrict access to the affected endpoint at the web server or WAF layer and verify no public upload path is exposed.
  • Audit the uploads directory and related web-accessible paths for unexpected PHP or other executable files.
  • Review web server logs for POST requests targeting upload.php and suspicious filename or extension manipulation.
  • Apply plugin updates or vendor guidance if a fixed version exists; if no fix is available, treat removal as the safest option.

Evidence notes

The source corpus provided by NVD states that Peugeot Music 1.0 contains an unauthenticated arbitrary file upload vulnerability via upload.php and the name parameter, with potential code execution from the uploads directory. Reference links in the record include an Exploit-DB entry and a VulnCheck advisory. The supplied CVE record was published/modified on 2026-05-17, which is the record timestamp used here.

Sources and references

Verified primary and authoritative sources

  • CVE-2018-25335 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2018-25335

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2018-25335 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2018-25335

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.