CVE-2025-60200: WordPress LearnPress Export Import plugin <= 4.1.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress LearnPress Export Import learnpress-import-export allows PHP Local File Inclusion.This issue affects LearnPress Export Import: from n/a through <= 4.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60200?
CVE-2025-60200 is classified as a high-severity vulnerability due to its potential for PHP Local File Inclusion.
How do I fix CVE-2025-60200?
To fix CVE-2025-60200, users should update the LearnPress Export Import plugin to version 4.1.0 or later.
What versions are affected by CVE-2025-60200?
CVE-2025-60200 affects LearnPress Export Import versions n/a through 4.0.9.
What impact does CVE-2025-60200 have on my site?
CVE-2025-60200 could allow an attacker to execute arbitrary PHP code by manipulating file inclusion patterns.
Who is the vendor for CVE-2025-60200?
The vendor for CVE-2025-60200 is ThimPress, the developer of the LearnPress Export Import plugin.