Remote File Inclusion Vulnerability in Xylus Themes XT Event Widget for Social Events
CVE-2025-47531

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 May 2025

What is CVE-2025-47531?

A vulnerability exists in the XT Event Widget for Social Events by Xylus Themes due to improper control of filenames when including or requiring PHP files. This flaw allows attackers to perform Local File Inclusion (LFI), potentially leading to unauthorized access to sensitive files on the server. The issue impacts versions from n/a through 1.1.7, making it crucial for users to review and update their installations to mitigate the risk associated with this threat.

Affected Version(s)

XT Event Widget for Social Events <= 1.1.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut (Patchstack Alliance)
.