First published: Thu Apr 03 2025(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NotFound include-file allows Path Traversal. This issue affects include-file: from n/a through 1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30596 has a medium severity level due to its potential for path traversal exploitation.
To fix CVE-2025-30596, update the NotFound include-file plugin to the latest version that addresses this vulnerability.
CVE-2025-30596 affects the NotFound include-file plugin in WordPress versions 1 and below.
CVE-2025-30596 is classified as a Path Traversal vulnerability, allowing unauthorized file access.
Yes, CVE-2025-30596 can be exploited remotely, presenting a risk to websites using the vulnerable plugin.