First published: Mon Mar 03 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Doctor Appointment Booking allows PHP Local File Inclusion. This issue affects Doctor Appointment Booking: from n/a through 1.0.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
NotFound Doctor Appointment Booking | <=1.0.0 | |
WordPress Doctor Appointment Booking Plugin | <=1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27264 has been classified as a critical severity vulnerability due to the potential for remote file inclusion attacks.
To fix CVE-2025-27264, update the NotFound Doctor Appointment Booking software to the latest version released after 1.0.0.
CVE-2025-27264 affects users of the NotFound Doctor Appointment Booking and the WordPress Doctor Appointment Booking Plugin up to version 1.0.0.
CVE-2025-27264 is classified as a Local File Inclusion vulnerability, allowing attackers to manipulate file inclusions through crafted input.
Attackers exploiting CVE-2025-27264 can execute arbitrary PHP code by including files from the local server, leading to further compromise.