PT-2026-4566 · WordPress · Kalrav Ai Agent

Ryan Kozak

·

Published

2026-01-24

·

Updated

2026-02-15

·

CVE-2025-13374

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kalrav AI Agent versions prior to 2.3.4
Description The Kalrav AI Agent plugin for WordPress is susceptible to arbitrary file uploads because of a lack of file type validation in the kalrav upload file AJAX action. This allows unauthenticated attackers to upload arbitrary files to the affected server, potentially leading to remote code execution. The kalrav upload file action is the component responsible for handling file uploads.
Recommendations Versions prior to 2.3.4 should be updated.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-13374

Affected Products

Kalrav Ai Agent