CVE-2025-14430: WordPress Brook - Agency Business Creative theme <= 2.9.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14430?
CVE-2025-14430 is classified as a high-severity vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-14430?
To fix CVE-2025-14430, update the ThemeMove Brook - Agency Business Creative to a version higher than 2.8.9.
What versions of ThemeMove Brook - Agency Business Creative are affected by CVE-2025-14430?
CVE-2025-14430 affects all versions of ThemeMove Brook - Agency Business Creative from an undefined version up to and including 2.8.9.
What type of vulnerability is CVE-2025-14430?
CVE-2025-14430 is a local file inclusion vulnerability that arises from improper control of filenames in PHP include or require statements.
Can CVE-2025-14430 lead to a website takeover?
Yes, if exploited, CVE-2025-14430 can potentially allow attackers to execute arbitrary PHP code and take control of affected websites.