CVE-2025-52728: WordPress Responsive Posts Carousel WordPress Plugin Plugin <= 15.0 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows PHP Local File Inclusion.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.0.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel WordPress Plugin allows PHP Local File Inclusion. This issue affects Responsive Posts Carousel WordPress Plugin: from n/a through 15.0.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52728?
CVE-2025-52728 is classified as a high severity vulnerability due to its potential for remote code execution via PHP Local File Inclusion.
How do I fix CVE-2025-52728?
To fix CVE-2025-52728, update the WebCodingPlace Responsive Posts Carousel WordPress Plugin to the latest version that addresses this vulnerability.
What versions of the WordPress plugin are affected by CVE-2025-52728?
CVE-2025-52728 affects the WebCodingPlace Responsive Posts Carousel WordPress Plugin version up to and including 15.0.
What type of vulnerability is CVE-2025-52728?
CVE-2025-52728 is an Improper Control of Filename for Include/Require Statement vulnerability, leading to local file inclusion.
Can CVE-2025-52728 lead to unauthorized access?
Yes, CVE-2025-52728 can allow attackers to gain unauthorized access to sensitive files on the server through local file inclusion.