PT-2025-48005 · WordPress · Projectlist

Ivan Cese

·

Published

2025-11-25

·

Updated

2025-11-30

·

CVE-2025-13376

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProjectList plugin for WordPress versions up to and including 0.3.0
Description The ProjectList plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation. This allows authenticated attackers with Editor-level access or higher to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Update the ProjectList plugin to a version newer than 0.3.0.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-13376

Affected Products

Projectlist