CVE-2025-48338: WordPress WP Abstracts plugin <= 2.7.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kevon Adonis WP Abstracts wp-abstracts-manuscripts-manager allows PHP Local File Inclusion.This issue affects WP Abstracts: from n/a through <= 2.7.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48338?
CVE-2025-48338 is classified as a critical severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2025-48338?
To mitigate CVE-2025-48338, upgrade the WP Abstracts plugin to version 2.7.5 or later.
What impact does CVE-2025-48338 have on my website?
CVE-2025-48338 can lead to local file inclusion, allowing attackers to access sensitive files on your server.
Which versions are affected by CVE-2025-48338?
CVE-2025-48338 affects WP Abstracts versions up to and including 2.7.4.
Is CVE-2025-48338 suitable for exploitation by a low-skilled attacker?
Yes, CVE-2025-48338 can be exploited by low-skilled attackers due to its simple exploitation method.