PT-2025-33149 · Wp Royal Themes · News Magazine X

Lvt-Tholv2K

·

Published

2025-08-14

·

Updated

2025-08-14

·

CVE-2025-24766

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WP Royal Themes News Magazine X versions through 1.2.37
Description: A flaw exists in WP Royal Themes News Magazine X related to improper control of filename for include/require statements, leading to a PHP Local File Inclusion issue. This allows for the inclusion of local files in PHP.
Recommendations: Update WP Royal Themes News Magazine X to a version beyond 1.2.37.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-24766

Affected Products

News Magazine X