CVE-2025-63076: WordPress The7 Elements plugin <= 2.7.11 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 Elements dt-the7-core allows PHP Local File Inclusion.This issue affects The7 Elements: from n/a through <= 2.7.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-63076?
CVE-2025-63076 has been classified as a high-severity vulnerability due to its potential for local file inclusion.
How do I fix CVE-2025-63076?
To mitigate CVE-2025-63076, upgrade The7 Elements plugin to version 2.7.12 or later.
What software is affected by CVE-2025-63076?
CVE-2025-63076 affects Dream-Theme The7 Elements versions up to and including 2.7.11.
What type of vulnerability is CVE-2025-63076?
CVE-2025-63076 is an improper control of filename for include/require statements in PHP.
Can CVE-2025-63076 lead to remote code execution?
While CVE-2025-63076 specifically allows for local file inclusion, it can be leveraged for further exploitation leading to remote code execution.