CVE-2025-39452: WordPress WPCafe plugin <= 2.2.32 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Arraytics WPCafe wp-cafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a through <= 2.2.32.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion. This issue affects WPCafe: from n/a through 2.2.32.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39452?
CVE-2025-39452 has a high severity rating due to its potential for remote file inclusion, which can lead to unauthorized access and execution of arbitrary code.
How do I fix CVE-2025-39452?
To fix CVE-2025-39452, update Themewinter WPCafe to the latest version or apply patches provided by the vendor.
What type of vulnerability is CVE-2025-39452?
CVE-2025-39452 is classified as a PHP Local File Inclusion vulnerability that can allow unauthorized access to local files.
Which versions of WPCafe are affected by CVE-2025-39452?
CVE-2025-39452 affects Themewinter WPCafe versions up to and including 2.2.32.
Can CVE-2025-39452 lead to data breaches?
Yes, CVE-2025-39452 can potentially lead to data breaches by allowing attackers to execute local files and gain sensitive information.