CVE-2025-13070
CSV to SortTable <= 4.2 - Contributor+ LFI
CVSS Score
6.6
EPSS Score
0.1%
EPSS Percentile
24th
The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.
| Vendor | unknown |
| Product | csv to sorttable |
| Published | Dec 9, 2025 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown csv to sorttable
Be the first to know when new medium vulnerabilities affecting unknown csv to sorttable are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / CSV to SortTable
0 โค 4.2
References
Credits
Ivan Cese WPScan