PT-2025-44934 · WordPress · Jewel Theme Recommended Plugins

Youcef Hamdani

·

Published

2025-11-04

·

Updated

2025-11-10

·

CVE-2025-10896

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress plugins with the Jewel Theme Recommended Plugins Library versions up to and including 1.0.2.3
Description The software is susceptible to unrestricted file upload due to missing capability checks within the * recommended upgrade plugin function. This allows authenticated attackers with subscriber-level access or higher to upload arbitrary plugin packages to the server by using a crafted plugin URL, potentially leading to remote code execution.
Recommendations Update to a version beyond 1.0.2.3.

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10896

Affected Products

Jewel Theme Recommended Plugins