First published: Wed May 07 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Chill Download Monitor allows PHP Local File Inclusion. This issue affects Download Monitor: from n/a through 5.0.22.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Chill Download Monitor | >=n/a<=5.0.22 | |
Download Monitor | <=5.0.22 |
Update the WordPress Download Monitor plugin to the latest available version (at least 5.0.23).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47439 has been classified as a critical vulnerability due to its potential for remote file inclusion.
To fix CVE-2025-47439, upgrade WP Chill Download Monitor to version 5.0.23 or later.
CVE-2025-47439 is caused by improper control of file names for include/require statements in the PHP code.
CVE-2025-47439 affects Download Monitor versions from n/a up to and including 5.0.22.
CVE-2025-47439 specifically affects the WP Chill Download Monitor environment within WordPress.