CVE 8.8 HIGH

Advanced Views – Display Posts, Custom Fields, and More <= 3.7.19 - Authenticated (Author+) Remote Code Execution via SSTI_CVE-2025-10380

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Advanced Views – Display Posts, Custom Fields, and More plugin for WordPress is vulnerable to Server-Side Template Injection in all versions up to, and including, 3.7.19. This is due to insufficient input sanitization and lack of access control when processing custom Twig templates in the Model panel. This makes it possible for authenticated attackers, with author-level access or higher, to execute arbitrary PHP code and commands on the server.

Basic Information

ID CVE-2025-10380
Source Wordfence
Published Sep 23, 2025 at 03:34

Affected Product

Vendor wplakeorg
Product Advanced Views – Display Posts, Custom Fields, and More
Version *
Affected Versions wplakeorg Advanced Views – Display Posts, Custom Fields, and More *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.