PHP Remote File Inclusion Vulnerability in Material Dashboard by Ho3einie
CVE-2025-31014

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 April 2025

What is CVE-2025-31014?

The Material Dashboard by Ho3einie is impacted by a vulnerability that allows for improper control of filename parameters within PHP programs, leading to potential PHP Local File Inclusion. This weakness allows attackers to exploit the software by including and executing malicious files on the server. The affected versions of Material Dashboard range from unverified releases to version 1.4.5, making it crucial for users to take immediate action to mitigate threats associated with this vulnerability.

Affected Version(s)

Material Dashboard 0 <= 1.4.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.