CVE-2025-30999: WordPress External Store for Shopify plugin <= 1.5.9 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fahad Mahmood External Store for Shopify wp-shopify allows PHP Local File Inclusion.This issue affects External Store for Shopify: from n/a through <= 1.5.9.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fahad Mahmood WP Shopify allows PHP Local File Inclusion. This issue affects WP Shopify: from n/a through 1.5.3.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30999?
CVE-2025-30999 is considered a critical vulnerability due to its potential for remote file inclusion leading to unauthorized access.
How do I fix CVE-2025-30999?
To fix CVE-2025-30999, update WP Shopify to version 1.5.4 or higher as this version includes a patch for the vulnerability.
What are the potential impacts of CVE-2025-30999?
The potential impacts of CVE-2025-30999 include unauthorized access to sensitive files and code execution on the web server.
Which versions of WP Shopify are affected by CVE-2025-30999?
CVE-2025-30999 affects all versions of WP Shopify up to and including version 1.5.3.
Who is the vendor for the CVE-2025-30999 vulnerability?
The vendor for the CVE-2025-30999 vulnerability is Fahad Mahmood.