Local File Inclusion Vulnerability in Formality by Michele Giorgi
CVE-2025-48157
8.1HIGH
What is CVE-2025-48157?
The vulnerability in Michele Giorgi's Formality plugin allows an attacker to execute malicious PHP code through improper control of filenames when including or requiring files in PHP scripts. This Local File Inclusion issue potentially enables attackers to access sensitive data or execute arbitrary commands on the server, posing a significant risk to affected users. All versions from the initial release through 1.5.9 are impacted, emphasizing the critical need for immediate patching and updates to safeguard against exploitation.
Affected Version(s)
Formality <= 1.5.9