PHP Remote File Inclusion Vulnerability in Improved Sale Badges – Free Version by Mihajlovic Nenad
CVE-2025-23949
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 January 2025
What is CVE-2025-23949?
A vulnerability exists in the Improved Sale Badges – Free Version developed by Mihajlovic Nenad, where improper control over filenames for include/require statements can lead to local file inclusion. This allows attackers to access sensitive files on the server, which may ultimately lead to exposure of critical data or execution of unauthorized code. Users of this plugin should ensure they are using the latest version and apply necessary security measures to mitigate this risk.
Affected Version(s)
Improved Sale Badges – Free Version <= 1.0.1