CVE-2025-10896HIGH 8.8EPSS p40.8%

CVE-2025-10896CVE-2025-10896

Description

Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of File with Dangerous Type via arbitrary plugin installation in all versions up to, and including, 1.0.2.3. This is due to missing capability checks on the '*_recommended_upgrade_plugin' function which allows arbitrary plugin URLs to be installed. This makes it possible for authenticated attackers with subscriber-level access and above to upload arbitrary plugin packages to the affected site's server via a crafted plugin URL, which may make remote code execution possible.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.53% probability of exploitation · percentile 40.8% · 2026-06-19T12:03:05Z
Published2025-11-04
Last modified2026-04-15

Underlying weaknesses· 1

CWE-862

References

  1. https://plugins.trac.wordpress.org/browser/image-hover-effects-elementor-addon/tags/1.0.2.3/Libs/Assets.php#L70
  2. https://plugins.trac.wordpress.org/browser/image-hover-effects-elementor-addon/tags/1.0.2.3/Libs/Recommended.php#L334
  3. https://plugins.trac.wordpress.org/browser/image-hover-effects-elementor-addon/tags/1.0.2.3/Libs/Recommended.php#L43
  4. https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3384308%40image-hover-effects-elementor-addon&new=3384308%40image-hover-effects-elementor-addon
  5. https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3389322%40image-comparison-elementor-addon&new=3389322%40image-comparison-elementor-addon
  6. https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3389341%40content-locker-for-elementor&new=3389341%40content-locker-for-elementor&sfp_email=&sfph_mail=
  7. https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3390374%40ultimate-blocks-for-gutenberg&new=3390374%40ultimate-blocks-for-gutenberg&sfp_email=&sfph_mail=
  8. https://www.wordfence.com/threat-intel/vulnerabilities/id/0ff3a292-3924-4823-867a-fedb2c1cdd00?source=cve

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-12153
CVE
CVE-2025-4317
CVE
CVE-2025-12682
CVE
CVE-2025-5395
CVE
CVE-2025-1304
CVE
CVE-2025-4403
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.