CVE-2025-22707: WordPress Moody theme <= 2.7.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.This issue affects Moody: from n/a through <= 2.7.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22707?
CVE-2025-22707 is considered a high severity vulnerability due to its potential for local file inclusion attacks.
How do I fix CVE-2025-22707?
To fix CVE-2025-22707, update the ThemeMove Moody to version 2.7.4 or later.
What software is affected by CVE-2025-22707?
CVE-2025-22707 affects the ThemeMove Moody theme in WordPress, specifically versions up to and including 2.7.3.
What type of vulnerability is CVE-2025-22707?
CVE-2025-22707 is classified as a PHP Remote File Inclusion vulnerability due to improper control of filename inclusion.
Can CVE-2025-22707 lead to arbitrary code execution?
Yes, if exploited, CVE-2025-22707 can potentially allow attackers to execute arbitrary code on the server.