CVE-2025-31016: WordPress JetWooBuilder plugin <= 2.1.18 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows PHP Local File Inclusion.This issue affects JetWooBuilder: from n/a through <= 2.1.18.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31016?
CVE-2025-31016 has a medium severity rating due to its potential for local file inclusion vulnerabilities.
How do I fix CVE-2025-31016?
To fix CVE-2025-31016, update NotFound JetWooBuilder to version 2.1.19 or later.
What is the impact of CVE-2025-31016?
CVE-2025-31016 allows unauthorized local file access, which could lead to sensitive information exposure on the server.
Is CVE-2025-31016 exploitable remotely?
CVE-2025-31016 is classified as a local file inclusion vulnerability, meaning exploitation requires local access to the server.
Which versions of JetWooBuilder are affected by CVE-2025-31016?
CVE-2025-31016 affects JetWooBuilder versions up to and including 2.1.18.