CVE-2025-60193: WordPress Premmerce User Roles plugin <= 1.0.13 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows PHP Local File Inclusion.This issue affects Premmerce User Roles: from n/a through <= 1.0.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60193?
CVE-2025-60193 is classified as a high-severity vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-60193?
To fix CVE-2025-60193, update the Premmerce User Roles plugin to version 1.0.14 or later as it addresses the vulnerability.
What systems are affected by CVE-2025-60193?
CVE-2025-60193 affects the Premmerce User Roles plugin for WordPress up to version 1.0.13.
What are the potential risks of CVE-2025-60193?
The risks of CVE-2025-60193 include unauthorized access to file systems and the execution of arbitrary code.
Who maintains the Premmerce User Roles plugin related to CVE-2025-60193?
The Premmerce User Roles plugin is maintained by Premmerce and is available for WordPress users.