CVE-2025-53565: WordPress Widget for Google Reviews <= 1.0.15 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews allows PHP Local File Inclusion. This issue affects Widget for Google Reviews: from n/a through 1.0.15.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Widget for Google Reviews business-reviews-wp allows PHP Local File Inclusion.This issue affects Widget for Google Reviews: from n/a through <= 1.0.15.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53565?
CVE-2025-53565 has a high severity due to its potential for PHP Local File Inclusion, which can lead to unauthorized code execution.
How do I fix CVE-2025-53565?
To fix CVE-2025-53565, update the Widget for Google Reviews to version 1.0.16 or higher.
What versions of the Widget for Google Reviews are affected by CVE-2025-53565?
CVE-2025-53565 affects versions up to and including 1.0.15 of the Widget for Google Reviews.
What type of vulnerability is CVE-2025-53565?
CVE-2025-53565 is categorized as a PHP Remote File Inclusion vulnerability, specifically related to improper control of filename handling.
Who is impacted by CVE-2025-53565?
Users of the Widget for Google Reviews from RadiusTheme or WordPress running versions 1.0.15 and below are impacted by CVE-2025-53565.