External risk intelligence

AR For WordPress Plugin CSRF Vulnerability Allows Web Shell Upload.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2025-60156

This vulnerability affects a WordPress plugin. WordPress sites are commonly deployed as public-facing web applications, and plugins are integral components of these web interfaces, making the vulnerable functionality frequently accessible via the public internet.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a WordPress plugin that could allow attackers to upload malicious code to web servers. This issue, a Cross-Site Request Forgery, impacts how the plugin handles user interactions, potentially enabling unauthorized code execution if a user is tricked into triggering the vulnerability. The primary concern is confirming if this plugin is in use and whether the specific affected versions are deployed within our environment, as this would necessitate further investigation into potential exposure.

  • A plugin flaw lets bad code onto servers.
  • Affects WordPress sites with specific plugin versions.
  • Confirm usage and versions to assess risk.

Attack Path

How an attacker could exploit the issue

An attacker could trick a logged-in administrator into visiting a malicious website, which then sends a request to the vulnerable WordPress plugin. This allows the attacker to upload a web shell to the server, potentially giving them control over the website.

  • No login required for attacker.
  • Triggered via a crafted link.
  • Allows arbitrary file upload.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to upload a web shell to the server when a user with sufficient privileges visits a malicious website. This could lead to the compromise of the web server and the data it hosts.

  • Web server integrity.
  • Via crafted web requests.
  • Server compromise and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for WordPress sites, including application owners, infrastructure, and platform teams, should prioritize addressing this vulnerability. The first practical step is to identify all instances of the affected WordPress plugin, confirm its exposure to external networks, and determine its business criticality to prioritize remediation efforts.

  • Application owners should assume responsibility.
  • Verify plugin presence and external reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the AR For WordPress plugin?

AR For WordPress is a specialized extension designed for WordPress websites to integrate augmented reality features. It manages the processing and display of 3D or AR content within the site's web interface. Plugins like this act as add-on modules that extend a core platform's functionality, often requiring specific permissions to handle file uploads or interact with server-side storage to manage media assets.

What does CWE-352 mean for CVE-2025-60156?

CWE-352 refers to Cross-Site Request Forgery (CSRF). This vulnerability class occurs when a web application fails to verify that an incoming request was intentionally sent by a legitimate user. In the context of this CVE, it means the plugin can be tricked into performing unauthorized actions, such as uploading files, because it relies on the user's active session rather than confirming the request's origin.

How is this CSRF vulnerability triggered?

An attacker triggers this by inducing an authenticated user, typically an administrator, to visit a malicious website while they are logged into the WordPress dashboard. The attacker's site sends a hidden, crafted request to the plugin. Notably, simply browsing the site or viewing a standard page does not trigger this; the malicious action requires the specific, manipulated request to be processed while the victim maintains an active, privileged session.

Why is this CVE considered relevant for my web server?

Halo Surface Signal indicates that because this is a WordPress plugin, it is often part of public-facing web interfaces, making it potentially accessible from the internet. If your site uses the affected version, the plugin's interaction with the server allows an attacker to bypass standard login requirements by leveraging an administrator's existing session to upload files that grant unauthorized control.

Do I need to take action if I run AR For WordPress?

Yes. First, perform an inventory to confirm if you are running version 8.34 or earlier. Once identified, evaluate the plugin's role in your environment and its exposure to external traffic. Because this flaw enables arbitrary file uploads and potential server compromise, you should treat identified instances as a high priority for remediation by updating or removing the plugin until a secure configuration is verified.

References