CVE-2025-26894: WordPress Coming Soon, Maintenance Mode plugin <= 1.1.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mobeen Abdullah Coming Soon, Maintenance Mode site-mode allows PHP Local File Inclusion.This issue affects Coming Soon, Maintenance Mode: from n/a through <= 1.1.1.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Coming Soon, Maintenance Mode allows PHP Local File Inclusion. This issue affects Coming Soon, Maintenance Mode: from n/a through 1.1.1.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26894?
CVE-2025-26894 is rated as a high-severity vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-26894?
To fix CVE-2025-26894, update the Coming Soon, Maintenance Mode plugin to version 1.1.2 or later.
What resources are affected by CVE-2025-26894?
CVE-2025-26894 affects the WordPress Coming Soon, Maintenance Mode plugin versions up to 1.1.1.
What type of vulnerability is CVE-2025-26894?
CVE-2025-26894 is classified as a Local File Inclusion vulnerability.
Can CVE-2025-26894 lead to significant security risks?
Yes, CVE-2025-26894 can lead to unauthorized access and execution of potentially malicious files on the server.