CVE-2025-49297: WordPress Grill and Chow theme <= 1.6 - Local File Inclusion Vulnerability
Published Jun 9, 2025
·Updated
Path Traversal: '.../...//' vulnerability in Mikado-Themes Grill and Chow grillandchow allows PHP Local File Inclusion.This issue affects Grill and Chow: from n/a through <= 1.6.
Affected Software
3 affected components
Mikado-Themes Grill>n/a, <=1.6
WordPress Grill and Chow<=1.6
Qodeinteractive Grill And Chow Wordpress<1.6.1
Remediation
Information
Update the WordPress Grill and Chow theme to the latest available version (at least 1.6.1).
Event History
Jun 9, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49297?
CVE-2025-49297 has been classified as a critical security vulnerability due to its potential for PHP Local File Inclusion.
2
How do I fix CVE-2025-49297?
To fix CVE-2025-49297, update Mikado-Themes Grill and Chow to the latest version beyond 1.6.
3
What types of systems are affected by CVE-2025-49297?
CVE-2025-49297 affects Mikado-Themes Grill and Chow versions from n/a to 1.6.
4
Can CVE-2025-49297 lead to exploitation?
Yes, CVE-2025-49297 can lead to exploitation via path traversal attacks allowing unauthorized file access.
5
Is CVE-2025-49297 specific to certain software versions?
CVE-2025-49297 specifically affects versions of Grill and Chow up to and including 1.6.