PHP Remote File Inclusion Vulnerability in Coming Soon, Maintenance Mode Plugin by NotFound
CVE-2025-26894
7.5HIGH
What is CVE-2025-26894?
The Coming Soon, Maintenance Mode plugin has a PHP Remote File Inclusion vulnerability that allows attackers to exploit improper controls over filename parameters. This vulnerability can lead to Local File Inclusion, enabling malicious entities to gain unauthorized access to sensitive files within the server. Users of versions up to 1.1.1 should take immediate action to secure their installations.
Affected Version(s)
Coming Soon, Maintenance Mode <= 1.1.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dimas Maulana (Patchstack Alliance)