CVE-2025-39466: WordPress Dør theme <= 2.4 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dør dor allows PHP Local File Inclusion.This issue affects Dør: from n/a through <= 2.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39466?
CVE-2025-39466 is classified as a medium severity vulnerability due to its potential for local file inclusion attacks.
How do I fix CVE-2025-39466?
To fix CVE-2025-39466, upgrade Mikado-Themes Dør to a version higher than 2.4.
What are the risks associated with CVE-2025-39466?
The risks associated with CVE-2025-39466 include unauthorized access to sensitive files and potential server compromise.
Which versions of Dør are affected by CVE-2025-39466?
CVE-2025-39466 affects all versions of Dør up to and including version 2.4.
What type of vulnerability is CVE-2025-39466?
CVE-2025-39466 is an improper control of filename for include/require statement vulnerability, leading to potential local file inclusion.