Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13070

Опубликовано: 09 дек. 2025
Источник: nvd
CVSS3: 6.6
EPSS Низкий

Описание

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

EPSS

Процентиль: 23%
0.00078
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.6
github
2 месяца назад

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

EPSS

Процентиль: 23%
0.00078
Низкий

6.6 Medium

CVSS3

Дефекты

CWE-22