Unauthenticated Media Upload Vulnerability in Listeo Core Plugin for WordPress
CVE-2025-14938
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 April 2026
What is CVE-2025-14938?
The Listeo Core plugin for WordPress contains a critical vulnerability that allows unauthenticated attackers to upload arbitrary media files to the site's media library. This stems from a lack of proper authorization and capability checks within the AJAX endpoint responsible for handling media uploads. By exploiting this weakness, attackers can bypass security measures, potentially leading to further malicious activities on the site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Listeo-Core - Directory Plugin by Purethemes 0 <= 2.0.27