CVE-2025-3123 | WonderCMS 3.5.0 Theme Installation/Plugin Installation installUpdateModuleAction unrestricted upload (Issue 330)
A vulnerability, which was classified as critical, has been found in WonderCMS 3.5.0. Affected by this issue is the function installUpdateModuleAction of the component Theme Installation/Plugin Installation. The manipulation leads to unrestricted upload.
This vulnerability is handled as CVE-2025-3123. The attack may be launched remotely. Furthermore, there is an exploit available.
The real existence of this vulnerability is still doubted at the moment.
The vendor explains, that "[t]he philosophy has always been, admin [...] bear responsibility to not install themes/plugins from untrusted sources."