CVE-2025-13536: Blubrry PowerPress <= 11.15.2 - Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post'
The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 11.15.2. This is due to the plugin validating file extensions but not halting execution when validation fails in the 'powerpresseditpost' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13536?
CVE-2025-13536 is considered a high severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2025-13536?
To fix CVE-2025-13536, update the Blubrry PowerPress plugin to the latest version that addresses the vulnerability.
What versions of Blubrry PowerPress are affected by CVE-2025-13536?
CVE-2025-13536 affects all versions of Blubrry PowerPress up to and including 11.15.2.
What types of attacks can be carried out using CVE-2025-13536?
Attackers can exploit CVE-2025-13536 to upload malicious files to the server, leading to possible remote code execution.
Is CVE-2025-13536 specific to particular installations of WordPress?
No, CVE-2025-13536 is a vulnerability in the Blubrry PowerPress plugin and can affect any WordPress installation using the vulnerable versions of the plugin.