The Blubrry PowerPress plugin has an Arbitrary File Upload vulnerability (CVE-2025-13536). A remote attacker with general user privileges can upload a malicious file and execute arbitrary code. Please confirm and patch as soon as possible.
The Tainacan plugin and Mascara theme have Improper Privilege Management vulnerabilities (CVE-2025-13538, CVE-2025-13540, and CVE-2025-13675). An unauthenticated remote attacker can specify an administrator role during registration, exploiting the vulnerability to gain website administrator privileges.
The FindAll Membership plugin has an Authentication Bypass vulnerability (CVE-2025-13539). An unauthenticated remote attacker who has obtained a general user account and can access the administrator's email can log into the system as an administrator.
The StreamTube Core plugin has an Arbitrary User Password Change vulnerability (CVE-2025-13615). An unauthenticated remote attacker can arbitrarily change website user passwords, potentially taking over an administrator account.
WordPress is a common website building system. Due to the large number of plugins and themes, serious vulnerabilities occasionally appear, such as the vulnerabilities listed in this alert.
It is recommended that when using a WordPress system, in addition to paying attention to updates for the WordPress core program, users must also monitor and promptly patch plugins and themes. Furthermore, it is recommended to evaluate the necessity of the plugins and themes being used, and remove them if they are not needed.