CVE-2025-26905: WordPress Estatik plugin <= 4.3.1 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik allows PHP Local File Inclusion.This issue affects Estatik: from n/a through <= 4.3.0.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estatik Estatik estatik allows PHP Local File Inclusion.This issue affects Estatik: from n/a through <= 4.3.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wordpress/estatikfrom your environment.If you cannot upgrade, uninstall the Estatik WordPress plugin (version <= 4.3.0) to eliminate the Local File Inclusion/path traversal exposure.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26905?
The severity of CVE-2025-26905 is classified as high due to the potential for local file inclusion attacks.
How do I fix CVE-2025-26905?
To fix CVE-2025-26905, update Estatik to version 4.2.0 or later immediately.
Which versions of Estatik are affected by CVE-2025-26905?
CVE-2025-26905 affects all Estatik versions up to and including 4.1.9.
What type of vulnerability is CVE-2025-26905?
CVE-2025-26905 is an improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability.
Can CVE-2025-26905 be exploited remotely?
Yes, CVE-2025-26905 can potentially be exploited remotely, allowing attackers to include local files.