PHP Remote File Inclusion Flaw in NotFound WP Food Ordering by NotFound
CVE-2025-31040

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 April 2025

What is CVE-2025-31040?

An improper control of filename in the include/require statements has been identified in the NotFound WP Food Ordering and Restaurant Menu plugin. This vulnerability allows for local file inclusion, which could lead to unauthorized access to sensitive files on the server. It is essential for users of this plugin version to ensure they apply necessary security measures to protect their systems.

Affected Version(s)

WP Food ordering and Restaurant Menu 0 <= 2.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.