CVE-2025-52806: WordPress JobSearch Plugin < 3.0.8 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch allows PHP Local File Inclusion. This issue affects JobSearch: from n/a through 2.9.0.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in eyecix JobSearch wp-jobsearch allows PHP Local File Inclusion.This issue affects JobSearch: from n/a through < 3.0.8.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52806?
CVE-2025-52806 has a high severity rating due to the potential for local file inclusion vulnerabilities.
How do I fix CVE-2025-52806?
To fix CVE-2025-52806, upgrade the Eyecix JobSearch to a version later than 2.9.0.
What causes the CVE-2025-52806 vulnerability?
CVE-2025-52806 is caused by improper control of filename for include/require statements in PHP.
Which software is affected by CVE-2025-52806?
CVE-2025-52806 affects Eyecix JobSearch and WordPress JobSearch Plugin versions up to and including 2.9.0.
Can CVE-2025-52806 lead to remote code execution?
CVE-2025-52806 primarily allows local file inclusion, which may lead to further exploitation but does not directly enable remote code execution.