PT-2025-44934 · WordPress · Jewel Theme Recommended Plugins
Youcef Hamdani
·
Published
2025-11-04
·
Updated
2025-11-10
·
CVE-2025-10896
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress plugins with the Jewel Theme Recommended Plugins Library versions up to and including 1.0.2.3
Description
The software is susceptible to unrestricted file upload due to missing capability checks within the
* recommended upgrade plugin function. This allows authenticated attackers with subscriber-level access or higher to upload arbitrary plugin packages to the server by using a crafted plugin URL, potentially leading to remote code execution.Recommendations
Update to a version beyond 1.0.2.3.
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jewel Theme Recommended Plugins