PT-2025-33467 · WordPress · Inpersttion For Theme

Peter Thaleikis

·

Published

2025-08-15

·

Updated

2025-08-15

·

CVE-2025-8905

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Inpersttion For Theme plugin for WordPress versions prior to 1.0
Description: The Inpersttion For Theme plugin for WordPress is susceptible to Remote Code Execution in versions up to and including 1.0 via the theme section shortcode() function. This is due to insufficient restrictions on callable functions, allowing authenticated attackers with Contributor-level access or higher to execute code on the server. The execution is limited to arbitrary functions without user-supplied parameters.
Recommendations: Update the Inpersttion For Theme plugin to a version newer than 1.0.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8905

Affected Products

Inpersttion For Theme