PHP Remote File Inclusion Vulnerability in Improved Sale Badges – Free Version by Mihajlovic Nenad
CVE-2025-23949

8.1HIGH

Key Information:

Vendor
Mihajlovic Nenad
Status
Improved Sale Badges – Free Version
Vendor
CVE Published:
22 January 2025

Summary

A vulnerability exists in the Improved Sale Badges – Free Version developed by Mihajlovic Nenad, where improper control over filenames for include/require statements can lead to local file inclusion. This allows attackers to access sensitive files on the server, which may ultimately lead to exposure of critical data or execution of unauthorized code. Users of this plugin should ensure they are using the latest version and apply necessary security measures to mitigate this risk.

Affected Version(s)

Improved Sale Badges – Free Version <= 1.0.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.