CVE-2025-25109: WordPress Vehicle Manager plugin <= 3.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky WP Vehicle Manager js-vehicle-manager allows PHP Local File Inclusion.This issue affects WP Vehicle Manager: from n/a through <= 3.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25109?
CVE-2025-25109 is classified as a high-severity vulnerability due to its potential for PHP Local File Inclusion.
How do I fix CVE-2025-25109?
To fix CVE-2025-25109, update the NotFound WP Vehicle Manager plugin to version 3.1 or later.
What versions of the WP Vehicle Manager are affected by CVE-2025-25109?
CVE-2025-25109 affects WP Vehicle Manager versions prior to and including 3.1.
What type of vulnerability is CVE-2025-25109?
CVE-2025-25109 is an Improper Control of Filename for Include/Require Statement vulnerability.
Can CVE-2025-25109 lead to remote code execution?
While CVE-2025-25109 is not a direct remote code execution vulnerability, it can enable attackers to include malicious files on the server.