Arbitrary File Upload Vulnerability in Starter Templates Plugin for WordPress
CVE-2025-13065
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 December 2025
What is CVE-2025-13065?
The Starter Templates plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate validation of file types. This issue, present in all versions up to 4.4.41, permits authenticated users with author-level access and above to upload malicious files disguised as WXR files. The vulnerability stems from a failure to properly sanitize file inputs, enabling the bypassing of security measures through the use of double extension files. Consequently, successful exploitation could lead to unauthorized remote code execution on the affected site's server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Starter Templates β AI-Powered Templates for Elementor & Gutenberg * <= 4.4.41
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved