CVE-2025-49935: WordPress WoodMart theme < 8.3.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in xtemos WoodMart woodmart allows PHP Local File Inclusion.This issue affects WoodMart: from n/a through < 8.3.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49935?
The severity of CVE-2025-49935 is considered critical due to its potential to allow unauthorized access to sensitive files on the server.
How do I fix CVE-2025-49935?
To fix CVE-2025-49935, update the WoodMart theme to version 8.3.2 or later to address the local file inclusion vulnerability.
What does CVE-2025-49935 affect?
CVE-2025-49935 affects the Xtemos WoodMart theme for WordPress versions prior to 8.3.2.
What is a remote file inclusion vulnerability in the context of CVE-2025-49935?
In the context of CVE-2025-49935, a remote file inclusion vulnerability allows attackers to include malicious files on the server using improper control of filename inputs.
Why is CVE-2025-49935 a concern for website owners using WoodMart?
CVE-2025-49935 is a concern for website owners using WoodMart as it can lead to exploitation by attackers to gain access to sensitive information or compromise the server.