Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19577 | The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. |
Mon, 07 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ptoffice
Ptoffice pt Project Notebooks |
|
| CPEs | cpe:2.3:a:ptoffice:pt_project_notebooks:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ptoffice
Ptoffice pt Project Notebooks |
Mon, 30 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 28 Jun 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. | |
| Title | PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation via wpnb_pto_new_users_add Function | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-06-30T18:32:41.019Z
Reserved: 2025-05-28T11:05:30.257Z
Link: CVE-2025-5304
Updated: 2025-06-30T18:32:36.691Z
Status : Analyzed
Published: 2025-06-28T06:15:22.173
Modified: 2025-07-07T14:47:29.020
Link: CVE-2025-5304
No data.
OpenCVE Enrichment
No data.
EUVD