CVE-2025-13070 - CERT CVE
ID CVE-2025-13070
Sažetak The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.
Reference
CVSS
Base: 6.6
Impact: 5.9
Exploitability:0.7
Pristup
VektorSloženostAutentikacija
NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH HIGH
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Zadnje važnije ažuriranje 11-12-2025 - 17:15
Objavljeno 09-12-2025 - 16:17