PHP Remote File Inclusion Vulnerability in CMSMasters Content Composer by Cmsmasters
CVE-2025-4414

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 July 2025

What is CVE-2025-4414?

The CMSMasters Content Composer is vulnerable to an improper control of filenames during include or require statements in PHP. This vulnerability allows for PHP Local File Inclusion, potentially leading to exposure of sensitive files on the server. Attackers could exploit this issue to manipulate file inclusions, resulting in unauthorized access to system files or executing arbitrary code. It is crucial for users and site administrators to prioritize updates and implement security measures to mitigate this vulnerability.

Affected Version(s)

CMSMasters Content Composer < 2.5.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.