Arbitrary File Upload Vulnerability in Starter Templates Plugin for WordPress
CVE-2025-13065
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 December 2025
What is CVE-2025-13065?
The Starter Templates plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate validation of file types. This issue, present in all versions up to 4.4.41, permits authenticated users with author-level access and above to upload malicious files disguised as WXR files. The vulnerability stems from a failure to properly sanitize file inputs, enabling the bypassing of security measures through the use of double extension files. Consequently, successful exploitation could lead to unauthorized remote code execution on the affected site's server.
Affected Version(s)
Starter Templates β AI-Powered Templates for Elementor & Gutenberg * <= 4.4.41