PT Luxa Addons <= 1.2.2 - Authenticated (Subscriber+) Arbitrary File Upload
high
The PT Luxa Addons plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 1.2.2. This is due to missing file type validation. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server, which...
- CVSS:
- 8.8
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 10, 2026
CVE-2025-60218 on NVD →
PT Luxa Addons <= 1.2.2 - Authenticated (Subscriber+) Arbitrary File Deletion
critical
The PT Luxa Addons plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lea...
- CVSS:
- 9.1
- Affected:
- up to 1.2.2
- Fix:
- No patched version reported
- Disclosed:
- Jun 10, 2025
CVE-2025-60217 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database