CVE-2025-15226

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

critical 9.8 CVSS 3.1
Published: Dec 29, 2025
Modified: Dec 31, 2025
Vendor: Sun.Net
Product: Wmpro

Description

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

References

Related CVEs