#VU125572 Improper input validation in Emlog Pro - CVE-2025-47787
Published: April 9, 2026
Emlog Pro
Emlog
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in /admin/store.php when downloading and installing remotely supplied ZIP plugin files. A remote user can send a specially crafted request with a malicious plugin archive URL to execute arbitrary code.
The issue occurs in the plugin installation functionality and requires access to initiate the remote plugin download request.