CVE-2025-39384: WordPress Product Lister for eBay plugin <= 2.0.9 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce Product Lister for eBay allows PHP Local File Inclusion. This issue affects Product Lister for eBay: from n/a through 2.0.9.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce Product Lister for eBay product-lister-ebay allows PHP Local File Inclusion.This issue affects Product Lister for eBay: from n/a through <= 2.0.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39384?
CVE-2025-39384 has a severity rating that indicates a high risk due to its potential for local file inclusion exploits.
How do I fix CVE-2025-39384?
To fix CVE-2025-39384, update the Product Lister for eBay to version 2.1.0 or higher, which addresses the vulnerability.
What products are affected by CVE-2025-39384?
CVE-2025-39384 affects CedCommerce Product Lister for eBay and WordPress Product Lister for eBay versions up to 2.0.9.
What types of attacks can CVE-2025-39384 facilitate?
CVE-2025-39384 can facilitate local file inclusion attacks, allowing an attacker to access sensitive files on the server.
Is CVE-2025-39384 exploitable remotely?
Yes, CVE-2025-39384 can be exploited remotely if the attacker can execute PHP code via the vulnerable plugin.