CVE-2025-13597
BaseFortify
Publication date: 2025-11-25
Last updated on: 2025-11-25
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | ai_feeds_plugin | 1.0.11 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The AI Feeds plugin for WordPress has a vulnerability in the 'actualizador_git.php' file where it lacks a capability check. This allows unauthenticated attackers to upload arbitrary files by downloading GitHub repositories and overwriting plugin files on the affected server. This can potentially lead to remote code execution.
How can this vulnerability impact me? :
This vulnerability can allow attackers to overwrite plugin files on your WordPress site, which may enable them to execute remote code. This can lead to full compromise of the affected server, data loss, defacement, or further attacks.