Local File Inclusion Vulnerability in SEUR Oficial PHP Software
CVE-2025-46474

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 May 2025

What is CVE-2025-46474?

An improper control of filename for include or require statements in the SEUR Oficial PHP application enables a local file inclusion vulnerability. This flaw permits unauthorized access to sensitive files on the server, which could potentially be exploited by malicious actors to execute arbitrary code or disclose sensitive information. All versions of SEUR Oficial up to 2.2.23 are impacted by this security issue, posing a significant risk to users who have not patched their installations.

Affected Version(s)

SEUR Oficial <= 2.2.23

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CĂşt lá»™n xĂ o me (Patchstack Alliance)
.