CVE-2025-5304: Ptoffice Pt Project Notebooks

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The PT Project Notebooks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization in the wpnb_pto_new_users_add() function in versions 1.0.0 through 1.1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

Affected products

  • Ptoffice Pt Project Notebooks: from 1.0.0, up to and including 1.1.3

Published 2025-06-28. Last modified 2026-06-17.