CVE-2025-60048: WordPress Tripster theme <= 1.0.10 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Tripster tripster allows PHP Local File Inclusion.This issue affects Tripster: from n/a through <= 1.0.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60048?
CVE-2025-60048 is considered a critical vulnerability due to its potential for remote file inclusion and local file manipulation.
How do I fix CVE-2025-60048?
To fix CVE-2025-60048, update the Tripster theme to a version later than 1.0.10.
What types of attacks can CVE-2025-60048 enable?
CVE-2025-60048 can enable attackers to execute arbitrary PHP code on the affected server via local file inclusion.
What software is affected by CVE-2025-60048?
CVE-2025-60048 affects the Tripster theme for WordPress, specifically versions up to and including 1.0.10.
How can I determine if my site is vulnerable to CVE-2025-60048?
Check if your WordPress site is using the Tripster theme version 1.0.10 or earlier to determine vulnerability to CVE-2025-60048.