Privilege Escalation Vulnerability in PT Project Notebooks for WordPress
CVE-2025-5304
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2025-5304?
The PT Project Notebooks plugin for WordPress contains a vulnerability that enables unauthenticated attackers to exploit missing authorization in the wpnb_pto_new_users_add() function. This deficiency allows individuals to elevate their privileges to that of an administrator, posing a significant security risk to affected installations. It is crucial for users to update to the latest version to mitigate this vulnerability and secure their WordPress environments.
Affected Version(s)
PT Project Notebooks – Take Meeting minutes, create budgets, track task management, and more 1.0.0 <= 1.1.3