---
id: CVE-2025-13070
title: >-
  The CSV to SortTable WordPress plugin through 4.2 does not validate some
  shortcode attributes before using them to generate paths passed to include
  function/s, allowing any authenticated users such as contributor to perform
  LFI attacks.
summary: >-
  The CSV to SortTable WordPress plugin through 4.2 does not validate some
  shortcode attributes before using them to generate paths passed to include
  function/s, allowing any authenticated users such as contributor to perform
  LFI attacks.
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13070'
references:
  - url: 'https://wpscan.com/vulnerability/deb52d69-d7f8-43a5-a709-1f543fd343c6/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00447
epssPercentile: 0.36733
ingestedAt: '2026-10-07T20:46:46.784Z'
---

## Overview

The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as contributor to perform LFI attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
