CVE-2025-68877: WordPress CedCommerce Integration for Good Market plugin <= 1.0.6 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CedCommerce CedCommerce Integration for Good Market allows PHP Local File Inclusion.This issue affects CedCommerce Integration for Good Market: from n/a through 1.0.6.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cedcommerce CedCommerce Integration for Good Market ced-good-market-integration allows PHP Local File Inclusion.This issue affects CedCommerce Integration for Good Market: from n/a through <= 1.0.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68877?
CVE-2025-68877 has a medium severity rating due to its potential for local file inclusion vulnerabilities.
How do I fix CVE-2025-68877?
To fix CVE-2025-68877, update the CedCommerce Integration for Good Market plugin to version 1.0.7 or later.
What versions of software are affected by CVE-2025-68877?
CVE-2025-68877 affects versions of CedCommerce Integration for Good Market from n/a to 1.0.6.
What type of vulnerability is CVE-2025-68877?
CVE-2025-68877 is classified as a PHP remote file inclusion vulnerability.
Can CVE-2025-68877 lead to remote code execution?
Yes, exploiting CVE-2025-68877 can lead to remote code execution through local file inclusion.