CVE-2025-48136: WordPress Mortgage Calculator Estatik plugin <= 2.0.12 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Estatik Mortgage Calculator Estatik estatik-mortgage-calculator allows PHP Local File Inclusion.This issue affects Mortgage Calculator Estatik: from n/a through <= 2.0.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48136?
CVE-2025-48136 is classified as a local file inclusion vulnerability, which can lead to unauthorized access to sensitive files.
How do I fix CVE-2025-48136?
To fix CVE-2025-48136, update the Estatik Mortgage Calculator to a version higher than 2.0.12 where the vulnerability has been patched.
What systems are affected by CVE-2025-48136?
CVE-2025-48136 specifically affects the Estatik Mortgage Calculator from versions n/a through 2.0.12.
Can CVE-2025-48136 allow remote code execution?
CVE-2025-48136 primarily allows local file inclusion, which can potentially lead to remote code execution if exploited correctly.
What impact does CVE-2025-48136 have on my website?
If exploited, CVE-2025-48136 can allow attackers to include files from the server, potentially compromising your website's security.