Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Unauthenticated arbitrary file upload in Kalrav AI Agent WordPress plugin (CVE-2025-13374)

The Kalrav AI Agent plugin for WordPress, in all versions up to and including 2.3.3, fails to validate file types in its kalrav_upload_file AJAX action, allowing unauthenticated attackers to upload arbitrary files to the server. The flaw may enable remote code execution on affected sites.

Disclosed 24 January 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can upload arbitrary files to affected WordPress sites, potentially achieving remote code execution.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2025-13374