CVE-2025-3491

HIGH

Add custom page template < 2.0.1 - Authenticated Remote Code Execution via 'template_name' Parameter

Title source: llm
STIX 2.1

Description

The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient sanitization of the 'template_name' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

Scores

CVSS v3 7.2
EPSS 0.0061
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
kiranpatil353/Add custom page template < 2.0.1
Published Apr 26, 2025
Tracked Since Feb 18, 2026