PHP Remote File Inclusion Vulnerability in WP OnlineSupport Hero Banner Ultimate
CVE-2025-22305

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 January 2025

What is CVE-2025-22305?

A vulnerability in the Hero Banner Ultimate plugin allows for improper control of filename in PHP include/require statements, potentially leading to local file inclusion. This susceptibility enables unauthorized access to files in the server's file system, compromising website security and allowing attackers to execute arbitrary code. Users of the Hero Banner Ultimate plugin versions up to 1.4.2 should take immediate action to secure their installations to prevent potential exploitation.

Affected Version(s)

Hero Banner Ultimate <= 1.4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.