Executive brief
PT Luxa Addons, a WordPress plugin used to extend website functionality, contains a critical security flaw that allows users with basic 'Subscriber' accounts to upload malicious files. An attacker could use this to upload a 'backdoor' script, granting them full control over the website, the ability to steal sensitive data, or the power to shut down the service entirely. This vulnerability is particularly dangerous because it requires very low technical skill to exploit once an account is created.
Technical details
The PT Luxa Addons plugin for WordPress (versions 1.2.2 and below) suffers from an Unrestricted File Upload vulnerability (CWE-434). The flaw allows authenticated attackers with Subscriber-level permissions to upload arbitrary files, such as PHP scripts, to the server. This occurs due to insufficient validation of file types and origins during the upload process. Successful exploitation enables remote code execution (RCE) on the underlying web server, potentially leading to full site takeover. As of the advisory date, no official patch has been released by the vendor.
Affected products
- WPLocker PT Luxa Addons <= 1.2.2
Timeline
- 2025-05-11: other: Vulnerability reported by researcher Bonds
- 2025-06-10: advisory: Patchstack published vulnerability details
- 2026-06-17: disclosed: CVE published to NVD