First published: Thu Apr 24 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WPoperation Opstore allows PHP Local File Inclusion. This issue affects Opstore: from n/a through 1.4.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPoperation Opstore | <=1.4.5 | |
WordPress Opstore | <=1.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39387 is classified as a high-severity vulnerability due to the potential for local file inclusion leading to code execution.
To fix CVE-2025-39387, upgrade WPoperation Opstore to version 1.4.6 or later, where the vulnerability has been addressed.
CVE-2025-39387 affects WPoperation Opstore versions up to and including 1.4.5.
CVE-2025-39387 is an Improper Control of Filename for Include/Require Statement vulnerability, specifically a PHP Local File Inclusion issue.
Yes, CVE-2025-39387 can potentially be exploited to execute code remotely, posing significant risk to affected applications.