First published: Wed Mar 26 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hostiko | <30.1 | |
WordPress Hostiko Theme | <30.1 |
Update the WordPress Hostiko wordpress theme to the latest available version (at least 30.1).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27015 is classified as a medium severity vulnerability due to its potential to allow local file inclusion.
To fix CVE-2025-27015, upgrade to the latest version of Hostiko that is above version 30.1.
CVE-2025-27015 can allow attackers to include local files and potentially execute malicious code on your server.
CVE-2025-27015 affects all versions of Hostiko prior to 30.1.
Yes, CVE-2025-27015 affects the WordPress Hostiko Theme up to version 30.1.