PT-2025-48005 · WordPress · Projectlist

Ivan Cese

·

Publicado

2025-11-25

·

Atualizado

2025-11-30

·

CVE-2025-13376

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProjectList plugin for WordPress versions up to and including 0.3.0
Description The ProjectList plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation. This allows authenticated attackers with Editor-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update the ProjectList plugin to a version newer than 0.3.0.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13376

Produtos afetados

Projectlist