A critical vulnerability (CVE-2025-60218) has been identified in PT Luxa Addons versions 1.2.2 and earlier. This issue enables an attacker to upload arbitrary files to a WordPress site using the plugin, potentially leading to remote code execution. The vulnerability affects all installations of the PT Luxa Addons plugin on WordPress platforms. Given the CVSS score of 9.9, this represents a critical risk to system integrity and data confidentiality. Attackers could exploit this flaw to deploy malicious payloads, compromise server access, or exfiltrate sensitive information. Users of the affected plugin versions are strongly advised to update to a patched version immediately. WordPress administrators should also review their plugin configurations and ensure proper file upload restrictions are enforced. Failure to address this vulnerability may result in severe security incidents, including full system compromise. Mitigation steps include applying the latest security patches and conducting regular vulnerability assessments.
CRITICAL
CVSS 9.9
CVE-2025-60218
2026-08-23
Critical Vulnerability in PT Luxa Addons Allows Arbitrary File Upload (CVE-2025-60218)
A critical vulnerability (CVE-2025-60218) allows attackers to upload arbitrary files via the PT Luxa Addons plugin for WordPress, affecting versions up to 1.2.2. This poses a high risk of remote code execution and data compromise.