Local File Inclusion Vulnerability in WP Shuffle Subscription Forms
CVE-2025-32692

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 April 2025

What is CVE-2025-32692?

A Local File Inclusion vulnerability in the WP Shuffle WP Subscription Forms plugin allows for the execution of potentially malicious PHP code. This flaw arises from improper control over filenames in include/require statements, enabling attackers to manipulate file paths and gain unauthorized access to the server. Users of WP Subscription Forms versions from n/a to 1.2.4 should take caution and consider updating to ensure their applications remain secure.

Affected Version(s)

WP Subscription Forms <= 1.2.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.