First published: Wed May 07 2025(Updated: )
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in tggfref WP-Recall allows PHP Local File Inclusion. This issue affects WP-Recall: from n/a through 16.26.14.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP-Recall | <=16.26.14 | |
WP-Recall | <=16.26.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-47653 is rated as a critical severity vulnerability due to its potential for allowing remote file inclusion and exploitation of the affected system.
To fix CVE-2025-47653, you should update the WP-Recall plugin to a version greater than 16.26.14.
CVE-2025-47653 affects all versions of the tggfref WP-Recall plugin up to and including version 16.26.14.
Yes, exploiting CVE-2025-47653 can potentially lead to a full server compromise by executing arbitrary PHP code.
Currently, the best course of action for CVE-2025-47653 is to remove or disable the WP-Recall plugin until an update is applied.