PT-2025-48251 · WordPress · Blubrry Powerpress

Ismailshadow

·

Published

2025-11-27

·

Updated

2025-11-29

·

CVE-2025-13536

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blubrry PowerPress versions up to and including 11.15.2
Description The Blubrry PowerPress plugin for WordPress is susceptible to arbitrary file uploads due to inadequate file type validation. This occurs because the plugin validates file extensions but does not stop processing when validation fails within the powerpress edit post function. Authenticated attackers with Contributor-level access or higher can exploit this to upload arbitrary files to the affected server, potentially leading to remote code execution.
Recommendations Versions up to and including 11.15.2 should be updated to a newer, fixed version. As a temporary workaround, consider restricting access to the powerpress edit post function to minimize the risk of exploitation.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-13536

Affected Products

Blubrry Powerpress