๐Ÿ” CVE Alert

CVE-2025-13070

MEDIUM 6.6

CSV to SortTable <= 4.2 - Contributor+ LFI

CVSS Score
6.6
EPSS Score
0.1%
EPSS Percentile
24th

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

Vendor unknown
Product csv to sorttable
Published Dec 9, 2025
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown csv to sorttable

Be the first to know when new medium vulnerabilities affecting unknown csv to sorttable are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / CSV to SortTable
0 โ‰ค 4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/deb52d69-d7f8-43a5-a709-1f543fd343c6/

Credits

Ivan Cese WPScan