CVE-2025-48125: WordPress WP Event Manager plugin <= 3.1.51 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager allows PHP Local File Inclusion. This issue affects WP Event Manager: from n/a through 3.1.49.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Event Manager WP Event Manager wp-event-manager allows PHP Local File Inclusion.This issue affects WP Event Manager: from n/a through <= 3.1.51.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48125?
CVE-2025-48125 has been classified as a high severity vulnerability due to its potential for local file inclusion, which can lead to unauthorized access or code execution.
How do I fix CVE-2025-48125?
To fix CVE-2025-48125, update WP Event Manager to the latest version beyond 3.1.49, which addresses this vulnerability.
What are the potential impacts of CVE-2025-48125?
The potential impacts of CVE-2025-48125 include unauthorized file access, system compromise, and possible server exploitation.
Who is affected by CVE-2025-48125?
Users of WP Event Manager versions up to and including 3.1.49 are affected by CVE-2025-48125.
Is CVE-2025-48125 a remote or local vulnerability?
CVE-2025-48125 is categorized as a local file inclusion vulnerability, meaning it can be exploited locally by attackers who have access to the system.