CVE-2025-13159 affects the Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress in all versions up to and including 1.0.43. The plugin exposes an unauthenticated AJAX endpoint, flo_form_submit, that permits SVG file uploads without proper validation of file contents. Because SVG is an XML-based format that can embed JavaScript and active content, an attacker can upload a crafted malicious SVG file and have that payload stored on the server. When a WordPress administrator later views the uploaded file from the admin interface, the embedded script executes in the administrator’s browser context. This is a stored cross-site scripting condition arising from unrestricted upload of dangerous file types and insufficient server-side content validation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
flo_form_submit AJAX endpoint. Block SVG uploads at the web server, WAF, or application layer, and review existing uploaded media or form-submitted files for malicious SVG content. Restrict administrator exposure by avoiding direct rendering of untrusted uploaded files in the admin interface where possible. Monitoring for unexpected AJAX submissions, suspicious SVG uploads, and anomalous administrator actions may help detect exploitation attempts.Patch, then assume compromise.
flo_form_submit should be corrected by enforcing strict server-side validation of uploaded files, disallowing SVG uploads by default unless they are robustly sanitized, and ensuring only safe file types are accepted. If SVG support is required, uploaded SVG content should be sanitized with a well-maintained allowlist-based sanitizer that removes scripts, event handlers, external references, and other active content.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.