First published: Thu Apr 24 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce Product Lister for eBay allows PHP Local File Inclusion. This issue affects Product Lister for eBay: from n/a through 2.0.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cedcommerce Product Lister for eBay | >=2.0.9 | |
WordPress Product Lister for eBay | <=2.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39384 has a severity rating that indicates a high risk due to its potential for local file inclusion exploits.
To fix CVE-2025-39384, update the Product Lister for eBay to version 2.1.0 or higher, which addresses the vulnerability.
CVE-2025-39384 affects CedCommerce Product Lister for eBay and WordPress Product Lister for eBay versions up to 2.0.9.
CVE-2025-39384 can facilitate local file inclusion attacks, allowing an attacker to access sensitive files on the server.
Yes, CVE-2025-39384 can be exploited remotely if the attacker can execute PHP code via the vulnerable plugin.