WordPress security by component
Biagiotti Core
Plugin description
Biagiotti Core is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 13, 2026; the highest published CVSS base score is 8.1.
Plugin slug:
biagiotti-coreLatest vulnerability
CVE-2026-66657: Biagiotti Core: Filesystem traversal
Biagiotti Core is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.1.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Aug 13, 2026 |
CVE-2026-66657
Biagiotti Core: Filesystem traversal
Biagiotti Core is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.1.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Sep 05, 2025 |
CVE-2025-9057
Biagiotti Core: Cross-site scripting
Biagiotti Core is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|