CVE-2025-13374: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13374 is an unauthenticated arbitrary file upload vulnerability in the Kalrav AI Agent plugin for WordPress, affecting all versions up to and including 2.3.3. The flaw resides in the kalrav_upload_file AJAX action, which lacks file type validation, nonce verification, and capability checks, enabling unauthenticated remote attackers to upload arbitrary files — including executable PHP scripts — potentially leading to remote code execution. The CVE was published on January 24, 2026, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The vulnerable function kalrav_upload_file() is registered via the wp_ajax_nopriv_kalrav_upload_file WordPress hook (line 967 of kalrav-ai-agent.php), which makes it accessible to unauthenticated users without any nonce or capability verification. User-supplied file data from $_FILES['file'] is processed with only a basename() call to prevent directory traversal, but no extension or MIME type validation is performed before the file is written to wp-content/plugins/kalrav-ai-agent/uploads/ via move_uploaded_file(). A public proof-of-concept exploit (CVE-2025-13374.py) is available on GitHub demonstrating upload of a PHP web shell and subsequent remote code execution (GitHub PoC, Researcher Write-up).

Impact

Successful exploitation allows an unauthenticated remote attacker to upload a PHP web shell to a publicly accessible directory on the WordPress server, enabling arbitrary command execution as the web server process (e.g., www-data). This can result in full compromise of the WordPress site — including theft of sensitive data (database credentials, user data), defacement, installation of backdoors, and lateral movement to other systems on the same hosting infrastructure. All three security pillars are affected: confidentiality, integrity, and availability (Wordfence, GitHub PoC).

Exploitability

A public proof-of-concept exploit script (CVE-2025-13374.py) was published on GitHub by researcher d0n601, demonstrating end-to-end exploitation including shell upload and command execution. As of the time of reporting, no patch is available for versions up to and including 2.3.3, and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.183%, indicating a relatively low but non-negligible probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has published a detection (ID: 530886) for this vulnerability (GitHub PoC, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Kalrav AI Agent plugin (version ≤ 2.3.3) using search engines, Shodan, or WordPress plugin enumeration tools. The plugin directory path wp-content/plugins/kalrav-ai-agent/ can be used as a fingerprint.
  2. Craft malicious upload request: Prepare a PHP web shell file (e.g., shell.php) containing a command execution payload such as <?php system($_GET['cmd']); ?>.
  3. Send unauthenticated upload request: Submit an HTTP POST request to the target's /wp-admin/admin-ajax.php endpoint with the parameter action=kalrav_upload_file and the PHP file attached as the file field in a multipart form-data body. No authentication, nonce, or session token is required.
  4. Retrieve uploaded shell URL: The server responds with a JSON success message containing the URL of the uploaded file, typically at http://<target>/wp-content/plugins/kalrav-ai-agent/uploads/<timestamp>-shell.php.
  5. Execute remote commands: Send HTTP GET requests to the shell URL with a command parameter (e.g., ?cmd=id) to execute arbitrary OS commands as the web server user (www-data), enabling further post-exploitation such as reverse shell establishment, credential harvesting, or lateral movement (GitHub PoC).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /wp-admin/admin-ajax.php with action=kalrav_upload_file from external or unknown IP addresses; subsequent GET requests to /wp-content/plugins/kalrav-ai-agent/uploads/*.php with command parameters (e.g., ?cmd=).
  • File System: Presence of unexpected .php files in the wp-content/plugins/kalrav-ai-agent/uploads/ directory, especially files with timestamp-prefixed names (e.g., 1763247725-shell.php); web shell content patterns such as system(), exec(), or passthru() in uploaded files.
  • Logs: Web server access logs showing POST requests to admin-ajax.php with action=kalrav_upload_file followed by GET requests to the uploads directory; PHP error logs showing execution of shell commands.
  • Process: Unusual child processes spawned by the web server process (e.g., www-data running bash, curl, wget, or python) (GitHub PoC, Wordfence).

Mitigation and workarounds

No official patch has been released for the Kalrav AI Agent plugin as of the time of reporting; all versions up to and including 2.3.3 remain vulnerable. Site administrators should immediately disable or remove the Kalrav AI Agent plugin from all affected WordPress installations. As a temporary measure, implement Web Application Firewall (WAF) rules to block POST requests to /wp-admin/admin-ajax.php with action=kalrav_upload_file, and restrict access to the wp-content/plugins/kalrav-ai-agent/uploads/ directory via server configuration (e.g., deny PHP execution in that directory). Review the uploads directory for any suspicious PHP files and remove them immediately (Wordfence, Wordfence Blog).

Community reactions

Wordfence, which discovered and reported the vulnerability, published it in their weekly WordPress vulnerability report for the week of January 19–25, 2026, highlighting its critical severity and unauthenticated nature. The vulnerability was picked up by TheHackerWire on Mastodon and Bluesky shortly after disclosure, and was featured in cybersecurity aggregators including CyberHub Blog and INCIBE. The public availability of a working PoC exploit on GitHub drew attention from the security community, with the vulnerability also indexed by Sploitus and Qualys for detection purposes (Wordfence Blog, Researcher Write-up).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management