Local File Inclusion Vulnerability in Formality by Michele Giorgi
CVE-2025-48157

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
20 August 2025

What is CVE-2025-48157?

The vulnerability in Michele Giorgi's Formality plugin allows an attacker to execute malicious PHP code through improper control of filenames when including or requiring files in PHP scripts. This Local File Inclusion issue potentially enables attackers to access sensitive data or execute arbitrary commands on the server, posing a significant risk to affected users. All versions from the initial release through 1.5.9 are impacted, emphasizing the critical need for immediate patching and updates to safeguard against exploitation.

Affected Version(s)

Formality <= 1.5.9

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Martino Spagnuolo (r3verii) (Patchstack Alliance)
.