← WordPress Vulnerabilities
WordPress security by component

Biagiotti Core

Biagiotti Core is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 13, 2026; the highest published CVSS base score is 8.1.

Plugin slug: biagiotti-core

CVE-2026-66657: Biagiotti Core: Filesystem traversal

Biagiotti Core is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.1.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedAug 13, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for biagiotti-core
Safe version
Aug 13, 2026 CVE-2026-66657
Biagiotti Core: Filesystem traversal
Biagiotti Core is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 2.1.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.1
NVDPending
Sep 05, 2025 CVE-2025-9057
Biagiotti Core: Cross-site scripting
Biagiotti Core is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending