CVE-2025-24782: WordPress Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate post-grid-carousel-ultimate allows PHP Local File Inclusion.This issue affects Post Grid, Slider & Carousel Ultimate: from n/a through <= 1.6.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24782?
CVE-2025-24782 is classified as a high severity vulnerability due to its potential for PHP Local File Inclusion, which can lead to severe security breaches.
How do I fix CVE-2025-24782?
To fix CVE-2025-24782, upgrade the wpWax Post Grid, Slider & Carousel Ultimate plugin to the latest version above 1.6.10.
What systems are affected by CVE-2025-24782?
CVE-2025-24782 affects the Post Grid, Slider & Carousel Ultimate plugin from versions prior to 1.6.10.
What type of vulnerability is CVE-2025-24782?
CVE-2025-24782 is an improper control of filename for include/require statement vulnerability, specifically a PHP Remote File Inclusion issue.
Is CVE-2025-24782 easily exploitable?
Yes, CVE-2025-24782 is considered easily exploitable, enabling attackers to execute arbitrary PHP code through local file inclusion.