CVE-2025-47533: WordPress Graphina plugin <= 3.0.4 - Cross Site Request Forgery (CSRF) to Local File Inclusion vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina allows PHP Local File Inclusion. This issue affects Graphina: from n/a through 3.0.4.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This issue affects Graphina: from n/a through <= 3.0.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47533?
CVE-2025-47533 is considered to be a high-severity vulnerability due to its potential for unauthorized access and local file inclusion.
How do I fix CVE-2025-47533?
To fix CVE-2025-47533, update the Iqonic Design Graphina plugin to the latest version beyond 3.0.4.
What types of attacks can CVE-2025-47533 enable?
CVE-2025-47533 can enable attacks such as Cross-Site Request Forgery (CSRF) and local file inclusion, potentially compromising the server.
Which software versions are affected by CVE-2025-47533?
CVE-2025-47533 affects Iqonic Design Graphina versions up to and including 3.0.4.
What is Cross-Site Request Forgery as related to CVE-2025-47533?
In the context of CVE-2025-47533, Cross-Site Request Forgery allows an attacker to trick a victim into executing unintended actions on a web application where they are authenticated.