Sploitus

CVE-2025-7443

1 known exploit for CVE-2025-7443

The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the store_javascript_cache.php file in all versions up to, and including, 2.2.42. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS 3.1
8.1 HIGH
EPSS
1.0% (60th percentile)
Weakness
CWE-434
NVD status
Deferred
Published
2025-08-01
CVE-2025-7443 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-7443

Proof-of-concept code and exploit modules indexed by Sploitus