PT-2026-27932 · Jwsthemes · Idealauto

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-25382

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions jwsthemes IdealAuto versions prior to 3.8.6
Description A flaw exists in the handling of filenames used in include/require statements within the PHP program, specifically in jwsthemes IdealAuto. This allows for PHP Local File Inclusion. The issue affects the IdealAuto software.
Recommendations Update jwsthemes IdealAuto to version 3.8.6 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-25382

Affected Products

Idealauto