First published: Thu Jan 16 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roninwp FAT Event Lite allows PHP Local File Inclusion.This issue affects FAT Event Lite: from n/a through 1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress FAT Event Lite | <=1.1 | |
WordPress FAT Event Lite | <=1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23915 is classified as a high severity vulnerability due to its potential for local file inclusion in affected versions.
To fix CVE-2025-23915, upgrade Roninwp FAT Event Lite to the latest version beyond 1.1 which addresses this vulnerability.
CVE-2025-23915 affects all versions of Roninwp FAT Event Lite up to and including 1.1.
CVE-2025-23915 is an improper control of filename for include/require statement vulnerability leading to PHP local file inclusion.
The vendor for CVE-2025-23915 is Roninwp, which develops the FAT Event Lite plugin for WordPress.