CVE-2025-13374Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-15: 1Patch / Workaround · 2026-02-15: 1Technical Details · 2026-02-15: 102-15
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    🔐 Critical #WordPress plugin flaw (CVE-2025-13374) found in the Kalrav AI Agent plugin (≤2.3.3) allows unauthenticated attackers to upload arbitrary files because of missing file type validation in an AJAX upload action. This can lead to remote code execution (#RCE) and full site compromise. 🛠️ Why it matters: Attackers don’t need credentials — they can push malicious scripts directly to your server through this flaw, risking data loss, defacement, or malware persistence on affected WordPress sites. 🔧 How to fix: Update the Kalrav AI Agent plugin to a patched version (≥2.3.4), remove it if unmaintained, and harden file upload endpoints with strict validation. #WordPressSecurity #WebSecurity #CVE #Malware #CyberThreats #CyberSecurity #PluginVulnerability

    Post summary

    The post highlights a critical WordPress plugin flaw (CVE‑2025‑13374) that enables unauthenticated file uploads and RCE, and it provides clear remediation steps by updating or removing the plugin.

    1000077
    37 followersView on X

Explore more