PHP Remote File Inclusion Vulnerability in Coming Soon, Maintenance Mode Plugin by NotFound
CVE-2025-26894

7.5HIGH

Key Information:

Vendor

Notfound

Vendor
CVE Published:
15 April 2025

What is CVE-2025-26894?

The Coming Soon, Maintenance Mode plugin has a PHP Remote File Inclusion vulnerability that allows attackers to exploit improper controls over filename parameters. This vulnerability can lead to Local File Inclusion, enabling malicious entities to gain unauthorized access to sensitive files within the server. Users of versions up to 1.1.1 should take immediate action to secure their installations.

Affected Version(s)

Coming Soon, Maintenance Mode <= 1.1.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.