🔐 CVE Alert

CVE-2025-5304

CRITICAL 9.8

PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation via wpnb_pto_new_users_add Function

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CWE CWE-862
Vendor blafoley
Product pt project notebooks – take meeting minutes, create budgets, track task management, and more
Published Jun 28, 2025
Last Updated Jun 30, 2025
Stay Ahead of the Next One

Get instant alerts for blafoley pt project notebooks – take meeting minutes, create budgets, track task management, and more

Be the first to know when new critical vulnerabilities affecting blafoley pt project notebooks – take meeting minutes, create budgets, track task management, and more are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

blafoley / PT Project Notebooks – Take Meeting minutes, create budgets, track task management, and more
1.0.0 ≤ 1.1.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/552ec9fc-5bff-4bee-be04-39892c89cd59?source=cve wordpress.org: https://wordpress.org/plugins/project-notebooks/#developers plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/project-notebooks/tags/1.1.3/includes/structure/admin/pto_admin_settings.php#L233 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/project-notebooks/tags/1.1.3/includes/structure/admin/pto_admin_settings.php#L36

Credits

Kenneth Dunn