CVE-2025-62066: WordPress Revolution theme < 2.5.8 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Revolution revolution.This issue affects Revolution: from n/a through < 2.5.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62066?
CVE-2025-62066 is classified as a critical vulnerability due to its potential to allow remote file inclusion, which can lead to unauthorized access and execution of malicious code.
How do I fix CVE-2025-62066?
To fix CVE-2025-62066, update your FuelThemes Revolution to version 2.5.8 or later, as this version addresses the vulnerability.
What versions of FuelThemes Revolution are affected by CVE-2025-62066?
CVE-2025-62066 affects all versions of FuelThemes Revolution prior to 2.5.8.
Can CVE-2025-62066 affect my WordPress site?
Yes, if you are using the WordPress version of FuelThemes Revolution below 2.5.8, your site is vulnerable to CVE-2025-62066.
What are the potential consequences of exploiting CVE-2025-62066?
Exploiting CVE-2025-62066 could allow an attacker to remotely execute code, potentially leading to data breaches or full system compromise.