Privilege Escalation Vulnerability in PT Project Notebooks for WordPress
CVE-2025-5304

9.8CRITICAL

What is CVE-2025-5304?

The PT Project Notebooks plugin for WordPress contains a vulnerability that enables unauthenticated attackers to exploit missing authorization in the wpnb_pto_new_users_add() function. This deficiency allows individuals to elevate their privileges to that of an administrator, posing a significant security risk to affected installations. It is crucial for users to update to the latest version to mitigate this vulnerability and secure their WordPress environments.

Affected Version(s)

PT Project Notebooks – Take Meeting minutes, create budgets, track task management, and more 1.0.0 <= 1.1.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.
CVE-2025-5304 : Privilege Escalation Vulnerability in PT Project Notebooks for WordPress