CVSS Score: 7.2 (High) Publicly Published: November 24, 2025 Last Updated: November 25, 2025 Researcher: Ivan Cese Description: - The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including 0.3.0. - This allows attackers with Editor+ capabilities to bypass authentication and manipulate files for unauthorized actions on the server. - Example: plugins.trac.wordpress.org ProjectList Details: - Software Type: Plugin - Software Slug: projectlist (view on wordpress.org) - Patched? No - Remediation: No known patch available. Review vulnerability details and apply mitigations based on organization's risk tolerance. Uninstall or find a replacement. - Affected Version: <= 0.3.0