CVE-2025-10723: PixelYourSite < 11.1.2 - Admin+ LFI
The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10723?
CVE-2025-10723 has a severity rating that indicates it allows unauthorized access to sensitive files via LFI attacks due to improper validation of URL parameters.
How do I fix CVE-2025-10723?
To fix CVE-2025-10723, update the PixelYourSite plugin to version 11.1.2 or later.
Who is affected by CVE-2025-10723?
Any WordPress site using the PixelYourSite plugin version prior to 11.1.2 is affected by CVE-2025-10723.
What types of attacks does CVE-2025-10723 allow?
CVE-2025-10723 allows Local File Inclusion (LFI) attacks which can expose sensitive files on the server.
Is user action required to mitigate CVE-2025-10723?
Yes, site administrators must take action by updating to the patched version of the PixelYourSite plugin to mitigate CVE-2025-10723.