CVE-2025-64377: WordPress ListingPro theme < 2.9.10 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CridioStudio ListingPro listingpro allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through < 2.9.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64377?
CVE-2025-64377 is classified as a high severity vulnerability due to its potential for remote file inclusion leading to arbitrary code execution.
How do I fix CVE-2025-64377?
To fix CVE-2025-64377, update to ListingPro version 2.9.10 or later, as this version addresses the vulnerability.
What systems are affected by CVE-2025-64377?
CVE-2025-64377 affects CridioStudio ListingPro versions earlier than 2.9.10.
Can CVE-2025-64377 lead to data breaches?
Yes, CVE-2025-64377 can potentially lead to data breaches through unauthorized file access and execution of malicious code.
Is CVE-2025-64377 a common vulnerability in PHP applications?
Yes, vulnerabilities like CVE-2025-64377 related to improper control of filenames for include/require statements are common in PHP applications.