← back to popular plugins
wordfence / plugin · supreme-modules-for-divi
Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder
supreme-modules-for-divi
total installs
200,000
total vulns
1
critical
0
high
1
medium
0
low
0
latest vuln
—
patched
1
unpatched
0
avg time to patch
—
vulnerabilities
(1)
Supreme Modules Lite <= 2.5.62 - Authenticated (Author+) Arbitrary File Upload via JSON Upload Bypass
high
✓ patched
cve id
CVE-2025-13062 ↗
cvss score
8.8
cwe
CWE-434: Unrestricted Upload of File with Dangerous Type
published
Jan 15, 2026
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.