CVE-2019-25295: Loopus Wp Cost Estimation & Payment Forms Builder
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site.
Affected products
- Loopus Wp Cost Estimation & Payment Forms Builder: before 9.660 (fixed in 9.660)
Published 2026-01-08. Last modified 2026-06-17.