CVE-2025-12138 | URL Image Importer Plugin up to 1.0.6 on WordPress PHP File uimptr_import_image_from_url unrestricted upload
A vulnerability, which was classified as critical, has been found in URL Image Importer Plugin up to 1.0.6 on WordPress. The impacted element is the function uimptr_import_image_from_url of the component PHP File Handler. The manipulation leads to unrestricted upload.
This vulnerability is documented as CVE-2025-12138. The attack can be initiated remotely. There is not any exploit available.