PHP Remote File Inclusion Vulnerability in Coming Soon, Maintenance Mode Plugin by NotFound
CVE-2025-26894
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 April 2025
What is CVE-2025-26894?
The Coming Soon, Maintenance Mode plugin has a PHP Remote File Inclusion vulnerability that allows attackers to exploit improper controls over filename parameters. This vulnerability can lead to Local File Inclusion, enabling malicious entities to gain unauthorized access to sensitive files within the server. Users of versions up to 1.1.1 should take immediate action to secure their installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Coming Soon, Maintenance Mode 0 <= 1.1.1