First published: Thu Apr 03 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator allows PHP Local File Inclusion. This issue affects DeBounce Email Validator: from n/a through 5.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress DeBounce Email Validator | >=n/a<=5.7 | |
WordPress DeBounce Email Validator | <=5.7 |
Update the WordPress DeBounce Email Validator plugin to the latest available version (at least 5.71).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31098 is rated as a high severity vulnerability due to its potential for remote file inclusion resulting in local file exposure.
To fix CVE-2025-31098, update the DeBounce Email Validator plugin to version 5.8 or later, which resolves the local file inclusion issue.
CVE-2025-31098 affects DeBounce Email Validator versions from n/a through 5.7.
CVE-2025-31098 can lead to unauthorized access to sensitive files on the web server, potentially compromising the security of your website.
CVE-2025-31098 is specific to the DeBounce Email Validator plugin and does not directly affect other plugins or applications.