PT-2025-24528 · Unknown · Unfoldwp Blogbyte

Published

2025-06-09

·

Updated

2025-06-09

·

CVE-2025-49275

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unfoldwp Blogbyte versions 1.1.1 and earlier
Description The issue is related to an Improper Control of Filename for Include/Require Statement in PHP Program, also known as 'PHP Remote File Inclusion', which allows PHP Local File Inclusion. This means that an attacker could potentially include and execute local files on the server, leading to unauthorized access or code execution.
Recommendations For Unfoldwp Blogbyte versions 1.1.1 and earlier, consider restricting access to sensitive files and directories to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and secure all include/require statements in PHP programs to prevent unauthorized file inclusions. Avoid using user-supplied input in filename variables to prevent malicious file inclusions.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-49275

Affected Products

Unfoldwp Blogbyte