CVE-2025-49921: WordPress JetReviews plugin <= 3.0.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-reviews allows PHP Local File Inclusion.This issue affects JetReviews: from n/a through <= 3.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49921?
CVE-2025-49921 is considered a high-severity vulnerability due to its potential for local file inclusion attacks.
How do I fix CVE-2025-49921?
To fix CVE-2025-49921, update the JetReviews plugin to version 3.0.1 or later immediately.
What software is affected by CVE-2025-49921?
CVE-2025-49921 affects CrocoBlock JetReviews and WordPress JetReviews versions up to and including 3.0.0.
What kind of attack can CVE-2025-49921 facilitate?
CVE-2025-49921 can facilitate local file inclusion attacks, which may lead to unauthorized access of sensitive files.
Is there a workaround for CVE-2025-49921 if I cannot update now?
As a temporary workaround for CVE-2025-49921, disable the JetReviews plugin until a patch can be applied.