PT-2025-39110 · WordPress · Advanced Views – Display Posts

·

CVE-2025-10380

·

Published

2025-09-23

·

Updated

2025-09-23

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress versions up to and including 3.7.19
Description The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is susceptible to Server-Side Template Injection. This is caused by inadequate input sanitization and a lack of access control when processing custom Twig templates in the Model panel. Authenticated attackers with author-level access or higher can potentially execute arbitrary PHP code and commands on the server. The vulnerability resides in how the plugin handles custom Twig templates, allowing for code execution through insufficient input validation.
Recommendations Update the Advanced Views – Display Posts, Custom Fields, and More plugin to a version beyond 3.7.19.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10380

Affected Products

Advanced Views – Display Posts