PT-2025-39110 · WordPress · Advanced Views – Display Posts

Aurélien Bourdois

·

Published

2025-09-23

·

Updated

2025-09-23

·

CVE-2025-10380

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress versions up to and including 3.7.19
Description The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is susceptible to Server-Side Template Injection. This is caused by inadequate input sanitization and a lack of access control when processing custom Twig templates in the Model panel. Authenticated attackers with author-level access or higher can potentially execute arbitrary PHP code and commands on the server. The vulnerability resides in how the plugin handles custom Twig templates, allowing for code execution through insufficient input validation.
Recommendations Update the Advanced Views – Display Posts, Custom Fields, and More plugin to a version beyond 3.7.19.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10380

Affected Products

Advanced Views – Display Posts