First published: Thu Apr 24 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Work Web Xews Lite allows PHP Local File Inclusion. This issue affects Xews Lite: from n/a through 1.0.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Code Work Xews Lite | >=n/a<=1.0.9 | |
WordPress Xews Lite plugin | <=1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39383 is rated as a medium severity vulnerability due to improper control of filename for include statements that can lead to local file inclusion.
To fix CVE-2025-39383, update the Code Work Xews Lite and WordPress Xews Lite plugin to the latest version beyond 1.0.9.
CVE-2025-39383 affects Code Work Xews Lite versions from n/a to 1.0.9 and the WordPress Xews Lite plugin up to version 1.0.9.
CVE-2025-39383 is not a remote attack vulnerability; it is a local file inclusion vulnerability that affects server-side scripts.
An attacker exploiting CVE-2025-39383 may gain unauthorized access to sensitive files on the server, potentially leading to further attacks.