CVE-2025-30820: WordPress WishSuite plugin <= 1.4.4 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in HT Plugins WishSuite wishsuite allows PHP Local File Inclusion.This issue affects WishSuite: from n/a through <= 1.4.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30820?
CVE-2025-30820 is categorized as a Local File Inclusion vulnerability, which can lead to unauthorized access to sensitive files on the server.
How do I fix CVE-2025-30820?
To fix CVE-2025-30820, update the WishSuite plugin to a version higher than 1.4.4.
What types of systems are affected by CVE-2025-30820?
CVE-2025-30820 affects all versions of HT Plugins WishSuite from n/a up to 1.4.4.
Can CVE-2025-30820 lead to remote code execution?
While CVE-2025-30820 is primarily a Local File Inclusion vulnerability, it could potentially allow attackers to execute arbitrary code if certain files are included.
Is CVE-2025-30820 related to WordPress?
Yes, CVE-2025-30820 also affects the WordPress version of the WishSuite plugin up to 1.4.4.