CVE-2025-48332: WordPress Gutenberg Blocks <= 3.3.1 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks advanced-gutenberg allows PHP Local File Inclusion.This issue affects Gutenberg Blocks: from n/a through <= 3.3.1.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48332?
CVE-2025-48332 is considered a high severity vulnerability due to the potential for local file inclusion.
How do I fix CVE-2025-48332?
To fix CVE-2025-48332, update PublishPress Gutenberg Blocks or WordPress Gutenberg Blocks to version 3.3.2 or later.
What systems are affected by CVE-2025-48332?
CVE-2025-48332 affects PublishPress Gutenberg Blocks and WordPress Gutenberg Blocks versions up to and including 3.3.1.
What is the impact of CVE-2025-48332?
The impact of CVE-2025-48332 allows attackers to exploit the vulnerability for local file inclusion, potentially leading to information disclosure.
Is there a workaround for CVE-2025-48332?
While the best solution is to update the plugin, a temporary workaround is to disable the affected plugins until a patch is applied.