Vulnerability Description
The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ptoffice | Pt Project Notebooks | >= 1.0.0, <= 1.1.3 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/project-notebooks/tags/1.1.3/includesProduct
- https://plugins.trac.wordpress.org/browser/project-notebooks/tags/1.1.3/includesProduct
- https://wordpress.org/plugins/project-notebooks/#developersProduct
- https://www.wordfence.com/threat-intel/vulnerabilities/id/552ec9fc-5bff-4bee-be0Third Party Advisory
FAQ
What is CVE-2025-5304?
CVE-2025-5304 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it...
How severe is CVE-2025-5304?
CVE-2025-5304 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-5304?
Check the references section above for vendor advisories and patch information. Affected products include: Ptoffice Pt Project Notebooks.