CVE-2025-30814: WordPress The Post Grid plugin <= 7.7.17 - Local File Inclusion vulnerability
Published Mar 27, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme The Post Grid the-post-grid allows PHP Local File Inclusion.This issue affects The Post Grid: from n/a through <= 7.7.17.
Affected Software
1 affected component
RadiusTheme The Post Grid<=7.7.17
Remediation
Information
Update the WordPress The Post Grid plugin to the latest available version (at least 7.7.18).
Event History
Mar 27, 2025
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-30814?
CVE-2025-30814 is classified as a critical vulnerability due to its potential for remote file inclusion.
2
How do I fix CVE-2025-30814?
To fix CVE-2025-30814, update The Post Grid plugin to version 7.7.18 or later.
3
What types of issues does CVE-2025-30814 cause?
CVE-2025-30814 allows for PHP Local File Inclusion, which can lead to unauthorized access to sensitive data on the server.
4
What versions are affected by CVE-2025-30814?
CVE-2025-30814 affects The Post Grid plugin versions up to and including 7.7.17.
5
Is CVE-2025-30814 specific to a certain software?
Yes, CVE-2025-30814 specifically affects the WordPress The Post Grid plugin.