CVE-2025-49307: WordPress WP Multilang plugin <= 2.4.19 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magazine3 WP Multilang allows PHP Local File Inclusion. This issue affects WP Multilang: from n/a through 2.4.19.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magazine3 WP Multilang wp-multilang allows PHP Local File Inclusion.This issue affects WP Multilang: from n/a through <= 2.4.19.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49307?
CVE-2025-49307 is classified as a critical vulnerability due to its potential for local file inclusion in WordPress WP Multilang.
How do I fix CVE-2025-49307?
To mitigate CVE-2025-49307, update WordPress WP Multilang to the latest version beyond 2.4.19.
What platforms are affected by CVE-2025-49307?
The vulnerability CVE-2025-49307 affects WordPress WP Multilang versions up to and including 2.4.19.
What kind of attacks can be executed using CVE-2025-49307?
Attackers can exploit CVE-2025-49307 to execute local file inclusion attacks, potentially compromising the server.
Is CVE-2025-49307 specific to any PHP version?
CVE-2025-49307 is not specifically tied to a particular PHP version but is related to the vulnerabilities within the WP Multilang plugin.