PT-2025-17356 · WordPress · Clever - Html5 Radio Player With History - Shoutcast/Icecast - Elementor Widget Addon

Khanhhnahk1

·

Published

2025-04-19

·

Updated

2025-04-20

·

CVE-2025-3103

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress versions up to, and including, 2.4
Description The issue is related to insufficient file path validation in the 'history.php' file, allowing unauthenticated attackers to read arbitrary files on the affected site's server. This may include sensitive information such as database credentials. The vulnerability was partially patched in version 2.4.
Recommendations For versions up to, and including, 2.4, update to a version that fully patches the vulnerability, as version 2.4 only partially addresses the issue. As a temporary workaround, consider restricting access to the 'history.php' file until a fully patched version is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-3103

Affected Products

Clever - Html5 Radio Player With History - Shoutcast/Icecast - Elementor Widget Addon