PT-2025-39951 · WordPress · Tiny Bootstrap Elements Light

Aril Aprilio

·

Published

2025-09-30

·

Updated

2025-10-05

·

CVE-2025-9991

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tiny Bootstrap Elements Light versions through 4.3.34
Description The Tiny Bootstrap Elements Light plugin for WordPress is susceptible to a Local File Inclusion issue via the language parameter. This allows unauthenticated attackers to include and execute arbitrary .php files on the server, potentially enabling the execution of PHP code within those files. Successful exploitation could lead to bypassing access controls and obtaining sensitive data.
Recommendations Update Tiny Bootstrap Elements Light to a version later than 4.3.34.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-9991

Affected Products

Tiny Bootstrap Elements Light