CVE-2025-49296: WordPress GrandPrix theme <= 1.6 - Local File Inclusion Vulnerability
Published Jun 9, 2025
·Updated
Path Traversal: '.../...//' vulnerability in Mikado-Themes GrandPrix grandprix allows PHP Local File Inclusion.This issue affects GrandPrix: from n/a through <= 1.6.
Affected Software
3 affected components
Mikado-Themes GrandPrix<=1.6
WordPress GrandPrix<=1.6
Qodeinteractive Grandprix Wordpress<1.6.1
Remediation
Information
Update the WordPress GrandPrix theme to the latest available version (at least 1.6.1).
Event History
Jun 9, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49296?
CVE-2025-49296 is classified as a high-severity path traversal vulnerability allowing local file inclusion.
2
How do I fix CVE-2025-49296?
To fix CVE-2025-49296, update Mikado-Themes GrandPrix to version 1.7 or later.
3
What versions are affected by CVE-2025-49296?
CVE-2025-49296 affects Mikado-Themes GrandPrix versions up to and including 1.6.
4
What are the potential impacts of CVE-2025-49296?
The potential impacts of CVE-2025-49296 include unauthorized access to sensitive files on the server.
5
Is CVE-2025-49296 specific to any platforms?
CVE-2025-49296 is specific to the Mikado-Themes GrandPrix theme used in WordPress.