CVE-2025-64364: WordPress Masterstudy theme < 4.8.126 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Masterstudy masterstudy allows PHP Local File Inclusion.This issue affects Masterstudy: from n/a through < 4.8.126.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64364?
CVE-2025-64364 is classified as a critical vulnerability due to its potential for remote file inclusion on affected versions of the Masterstudy theme.
How do I fix CVE-2025-64364?
To remediate CVE-2025-64364, update the Masterstudy theme to version 4.8.126 or higher.
Which versions of Masterstudy are affected by CVE-2025-64364?
CVE-2025-64364 affects all versions of Masterstudy theme prior to version 4.8.126.
Can CVE-2025-64364 lead to unauthorized access?
Yes, CVE-2025-64364 can allow attackers to execute arbitrary code due to local file inclusion, potentially leading to unauthorized access.
Is CVE-2025-64364 exploitable on all configurations?
CVE-2025-64364 is exploitable under specific conditions based on the configuration of the affected server and theme settings.