CVE-2025-47440: WordPress WPAdverts plugin <= 2.2.2 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Greg Winiarski WPAdverts allows PHP Local File Inclusion. This issue affects WPAdverts: from n/a through 2.2.2.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Greg Winiarski WPAdverts wpadverts allows PHP Local File Inclusion.This issue affects WPAdverts: from n/a through <= 2.2.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47440?
CVE-2025-47440 is categorized as a high-severity vulnerability due to the potential for local file inclusion, which could lead to unauthorized access to sensitive files.
How do I fix CVE-2025-47440?
To fix CVE-2025-47440, update the WPAdverts plugin to version 2.2.3 or later, which addresses the vulnerability.
What software is affected by CVE-2025-47440?
CVE-2025-47440 affects the WPAdverts plugin versions up to and including 2.2.2.
What kind of attack is possible with CVE-2025-47440?
CVE-2025-47440 allows attackers to perform local file inclusion attacks, potentially leading to the exposure of sensitive information.
Is CVE-2025-47440 related to remote file inclusion?
Yes, CVE-2025-47440 is a type of local file inclusion vulnerability, but it is often discussed in the context of remote file inclusion issues due to similarities in exploitation techniques.