PT-2025-17356 · WordPress · Clever - Html5 Radio Player With History - Shoutcast/Icecast - Elementor Widget Addon
Khanhhnahk1
·
Published
2025-04-19
·
Updated
2025-04-20
·
CVE-2025-3103
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress versions up to, and including, 2.4
Description
The issue is related to insufficient file path validation in the 'history.php' file, allowing unauthenticated attackers to read arbitrary files on the affected site's server. This may include sensitive information such as database credentials. The vulnerability was partially patched in version 2.4.
Recommendations
For versions up to, and including, 2.4, update to a version that fully patches the vulnerability, as version 2.4 only partially addresses the issue.
As a temporary workaround, consider restricting access to the 'history.php' file until a fully patched version is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clever - Html5 Radio Player With History - Shoutcast/Icecast - Elementor Widget Addon