CVE-2025-54034: WordPress Newsletters plugin <= 4.10 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletters allows PHP Local File Inclusion. This issue affects Newsletters: from n/a through 4.10.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletters newsletters-lite allows PHP Local File Inclusion.This issue affects Newsletters: from n/a through <= 4.10.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54034?
CVE-2025-54034 has been classified as a high-severity vulnerability due to its potential for PHP Local File Inclusion.
How do I fix CVE-2025-54034?
To fix CVE-2025-54034, update the Tribulant Software Newsletters plugin to the latest version above 4.10.
What systems are affected by CVE-2025-54034?
CVE-2025-54034 affects the Tribulant Software Newsletters plugin, version n/a up to 4.10.
What type of vulnerability is CVE-2025-54034?
CVE-2025-54034 is categorized as a Remote File Inclusion vulnerability that allows local file inclusion in PHP.
Can CVE-2025-54034 lead to remote exploitation?
While CVE-2025-54034 primarily facilitates Local File Inclusion, it may also be exploited to execute code remotely under certain circumstances.