CVE-2025-63017: WordPress WerkStatt plugin plugin <= 1.6.6 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes WerkStatt Plugin werkstatt-plugin allows PHP Local File Inclusion.This issue affects WerkStatt Plugin: from n/a through <= 1.6.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63017?
CVE-2025-63017 is considered a high-severity Local File Inclusion vulnerability.
How do I fix CVE-2025-63017?
To fix CVE-2025-63017, users should update the WerkStatt Plugin to a version higher than 1.6.6.
What types of systems are affected by CVE-2025-63017?
CVE-2025-63017 affects any WordPress site using version 1.6.6 or lower of the WerkStatt Plugin.
What can an attacker exploit in CVE-2025-63017?
An attacker can exploit CVE-2025-63017 to execute local files on the server, potentially leading to remote file inclusion.
Is there an official patch for CVE-2025-63017?
Yes, the vulnerability has been addressed in versions of the WerkStatt Plugin released after 1.6.6.