CVE-2025-47586: WordPress Motors - Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events allows PHP Local File Inclusion.This issue affects Motors - Events: from n/a through 1.4.7.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PHP Local File Inclusion.This issue affects Motors - Events: from n/a through <= 1.4.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47586?
CVE-2025-47586 is classified as a high severity vulnerability due to its potential for remote file inclusion exploitation.
How do I fix CVE-2025-47586?
To fix CVE-2025-47586, upgrade to a version of StylemixThemes Motors - Events that is higher than 1.4.7.
What impact does CVE-2025-47586 have on my site?
CVE-2025-47586 can allow unauthorized users to include arbitrary files on the server, compromising site integrity.
Is CVE-2025-47586 specific to certain versions?
Yes, CVE-2025-47586 affects all versions of StylemixThemes Motors - Events up to and including 1.4.7.
Who is affected by CVE-2025-47586?
Anyone using StylemixThemes Motors - Events or WordPress Motors - Events versions up to 1.4.7 is potentially affected by CVE-2025-47586.