First published: Mon Mar 03 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Vehicle Manager allows PHP Local File Inclusion. This issue affects WP Vehicle Manager: from n/a through 3.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Vehicle Manager | <=3.1 | |
WP Vehicle Manager | <=3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25109 is classified as a high-severity vulnerability due to its potential for PHP Local File Inclusion.
To fix CVE-2025-25109, update the NotFound WP Vehicle Manager plugin to version 3.1 or later.
CVE-2025-25109 affects WP Vehicle Manager versions prior to and including 3.1.
CVE-2025-25109 is an Improper Control of Filename for Include/Require Statement vulnerability.
While CVE-2025-25109 is not a direct remote code execution vulnerability, it can enable attackers to include malicious files on the server.