First published: Tue Apr 15 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound hockeydata LOS allows PHP Local File Inclusion. This issue affects hockeydata LOS: from n/a through 1.2.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
hockeydata LOS plugin | >=n/a<1.2.4 | |
hockeydata LOS plugin | <=1.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26889 is considered a high-severity vulnerability due to its potential for local file inclusion, which may lead to serious security breaches.
To fix CVE-2025-26889, update the hockeydata LOS plugin to version 1.2.5 or later, which resolves the local file inclusion issue.
CVE-2025-26889 affects hockeydata LOS versions from n/a through 1.2.4 and the corresponding WordPress hockeydata LOS plugin.
CVE-2025-26889 is categorized as a Remote File Inclusion vulnerability affecting PHP programs.
Yes, CVE-2025-26889 can potentially allow attackers to access sensitive files on the server, leading to data exposure.