Arbitrary File Upload Vulnerability in Starter Templates Plugin for WordPress
CVE-2025-13065

8.8HIGH

What is CVE-2025-13065?

The Starter Templates plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate validation of file types. This issue, present in all versions up to 4.4.41, permits authenticated users with author-level access and above to upload malicious files disguised as WXR files. The vulnerability stems from a failure to properly sanitize file inputs, enabling the bypassing of security measures through the use of double extension files. Consequently, successful exploitation could lead to unauthorized remote code execution on the affected site's server.

Affected Version(s)

Starter Templates – AI-Powered Templates for Elementor & Gutenberg * <= 4.4.41

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.
CVE-2025-13065 : Arbitrary File Upload Vulnerability in Starter Templates Plugin for WordPress