PT-2026-1685 · WordPress · Wp Cost Estimation

Mikey Veenstra

·

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2019-25296

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Cost Estimation versions up to and including 9.642
Description The WP Cost Estimation plugin for WordPress is affected by a flaw allowing arbitrary file uploads and deletion. This is due to a lack of file type validation in the lfb upload form and lfb removeFile AJAX actions. An unauthenticated attacker can upload arbitrary files to the affected server, potentially leading to remote code execution. The attacker can also delete files, including database configuration files, and replace them with their own.
Recommendations Update WP Cost Estimation to a version beyond 9.642.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2019-25296

Affected Products

Wp Cost Estimation