CVE-2025-13786 is a critical code injection vulnerability affecting taosir WTCMS up to commit 01a5f68a3dfc2fdddb44eed967bb2d4f60487665, specifically within the fetch function of the /index.php file. This vulnerability, rated 9.8 Critical on CVSS, allows for remote, unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While the exploit is publicly available, there is no evidence of active exploitation, and it lacks significant community discussion or media coverage. The vendor has not responded to disclosure attempts, and due to a rolling release model, specific affected or updated versions are unavailable.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019-12-20CPE matchmatch criteria | cpe:2.3:a:wtcms_project:wtcms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.