Local File Inclusion Vulnerability in WP Shuffle Subscription Forms
CVE-2025-32692
7.5HIGH
What is CVE-2025-32692?
A Local File Inclusion vulnerability in the WP Shuffle WP Subscription Forms plugin allows for the execution of potentially malicious PHP code. This flaw arises from improper control over filenames in include/require statements, enabling attackers to manipulate file paths and gain unauthorized access to the server. Users of WP Subscription Forms versions from n/a to 1.2.4 should take caution and consider updating to ensure their applications remain secure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Subscription Forms <= 1.2.4
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
LVT-tholv2k (Patchstack Alliance)