PT-2025-22730 · Unknown+1 · Wpfable Fable Extra+1

Stealthcopter

·

Published

2025-05-23

·

Updated

2025-05-23

·

CVE-2025-46468

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPFable Fable Extra versions 1.0.0 through 1.0.6
Description The issue is related to an Improper Control of Filename for Include/Require Statement in PHP Program, also known as 'PHP Remote File Inclusion', which allows PHP Local File Inclusion.
Recommendations For versions 1.0.0 through 1.0.6, consider restricting access to vulnerable include or require statements in PHP programs to minimize the risk of exploitation. As a temporary workaround, consider disabling the use of user-supplied input in include or require statements until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-46468

Affected Products

Php
Wpfable Fable Extra