CVE-2025-12813: Holiday class post calendar <= 7.1 - Unauthenticated Remote Code Execution via 'contents'
The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitization of user-supplied data when creating a cache file. This makes it possible for unauthenticated attackers to execute code on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12813?
The severity of CVE-2025-12813 is classified as high due to the potential for remote code execution.
How do I fix CVE-2025-12813?
To fix CVE-2025-12813, update the Holiday class post calendar plugin to version 7.2 or later.
Which versions are affected by CVE-2025-12813?
CVE-2025-12813 affects all versions of the Holiday class post calendar plugin up to and including version 7.1.
What is the attack vector for CVE-2025-12813?
The attack vector for CVE-2025-12813 is via the 'contents' parameter, which is not properly sanitized.
Can CVE-2025-12813 be exploited without authentication?
Yes, CVE-2025-12813 can be exploited without authentication, allowing unauthenticated attackers to execute code.