VYPR
Medium severity5.3NVD Advisory· Published Apr 4, 2026· Updated Apr 24, 2026

CVE-2025-14938

CVE-2025-14938

Description

The Listeo Core plugin for WordPress is vulnerable to unauthenticated arbitrary media upload in all versions up to, and including, 2.0.27 via the "listeo_core_handle_dropped_media" function. This is due to missing authorization and capability checks on the AJAX endpoint handling file uploads. This makes it possible for unauthenticated attackers to upload arbitrary media to the site's media library, without achieving direct code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated arbitrary media upload in Listeo Core plugin up to 2.0.27 via missing authorization on AJAX endpoint.

The Listeo Core plugin for WordPress versions up to and including 2.0.27 is vulnerable to unauthenticated arbitrary media upload. The 'listeo_core_handle_dropped_media' function lacks authorization and capability checks on the AJAX endpoint handling file uploads [1].

An unauthenticated attacker can exploit this by sending crafted requests to the AJAX endpoint, uploading arbitrary media files to the site's media library without any authentication [1]. The vulnerability does not directly allow code execution, but uploaded media can be used for further attacks.

While direct code execution is not achieved, attackers can upload arbitrary media, potentially leading to stored cross-site scripting (XSS) if the media is displayed on the site, or filling the media library with unwanted content [1].

The vulnerability is addressed in version 2.0.36 of the plugin, as per the changelog [1]. Users are strongly advised to update to the latest version to mitigate the risk.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1