CVE-2025-46230: WordPress Popup Builder plugin <= 1.1.35 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder allows PHP Local File Inclusion. This issue affects Popup Builder: from n/a through 1.1.35.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local File Inclusion.This issue affects Popup Builder: from n/a through <= 1.1.35.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46230?
CVE-2025-46230 has a medium severity rating due to its potential for local file inclusion vulnerabilities.
How do I fix CVE-2025-46230?
To fix CVE-2025-46230, update the GhozyLab Popup Builder to version 1.1.36 or later.
Which versions of GhozyLab Popup Builder are affected by CVE-2025-46230?
GhozyLab Popup Builder versions up to and including 1.1.35 are affected by CVE-2025-46230.
What type of vulnerability is CVE-2025-46230?
CVE-2025-46230 is classified as a PHP Remote File Inclusion vulnerability.
Can CVE-2025-46230 affect WordPress installations?
Yes, CVE-2025-46230 can affect WordPress installations that use the GhozyLab Popup Builder up to version 1.1.35.