Path Traversal Vulnerability in NotFound Include-File by WordPress
CVE-2025-30596
6.5MEDIUM
What is CVE-2025-30596?
A vulnerability exists in the NotFound include-file for WordPress that allows attackers to exploit improper limitations on file path inputs. This security flaw can lead to unauthorized access to restricted directories, enabling attackers to manipulate pathnames. As a result, unauthorized files may be read or executed, potentially compromising the integrity of the website and exposing sensitive data.
Affected Version(s)
include-file <= 1