CVE-2025-53259: WordPress Hotel Booking plugin <= 3.7 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking allows PHP Local File Inclusion. This issue affects Hotel Booking: from n/a through 3.7.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nicdark Hotel Booking nd-booking allows PHP Local File Inclusion.This issue affects Hotel Booking: from n/a through <= 3.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53259?
CVE-2025-53259 is classified as a critical vulnerability due to its potential for remote file inclusion and subsequent exploitation.
How do I fix CVE-2025-53259?
To fix CVE-2025-53259, upgrade the Nicdark Hotel Booking software to version 3.8 or later, which addresses this local file inclusion vulnerability.
Which versions are affected by CVE-2025-53259?
CVE-2025-53259 affects Nicdark Hotel Booking versions up to and including 3.7.
What can attackers do by exploiting CVE-2025-53259?
Attackers exploiting CVE-2025-53259 can potentially execute arbitrary PHP code on the server, leading to full server compromise.
Is the WordPress Hotel Booking plugin also affected by CVE-2025-53259?
Yes, the WordPress Hotel Booking plugin versions up to and including 3.7 are also affected by CVE-2025-53259.