CVE 9 CRITICAL

WordPress WP Webhooks plugin <= 3.3.8 - Arbitrary File Upload vulnerability_CVE-2025-66074

9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Path Traversal.This issue affects WP Webhooks: from n/a through <= 3.3.8.

AI Analysis

Arbitrary File Upload vulnerability in WP Webhooks plugin

Basic Information

ID CVE-2025-66074
Source Patchstack
Published Dec 18, 2025 at 07:22
Modified Dec 18, 2025 at 15:51

Affected Product

Vendor Cozmoslabs
Product WP Webhooks
Version n/a
Affected Versions Cozmoslabs WP Webhooks n/a

CWE Classification

AI Assessment

AI Score 9 / 10
AI Severity Critical
Vendor Cozmoslabs
Product WP Webhooks
Version <= 3.3.8

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.