PHP Remote File Inclusion Vulnerability in ThemBay Cena Store
CVE-2025-48171

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-48171?

The ThemBay Cena Store features a vulnerability that allows remote file inclusion, whereby malicious actors could manipulate the file paths in PHP's Include/Require statements. This flaw could enable unauthorized access to sensitive files on the server, escalating the risk of further exploitation. Users of Cena Store versions prior to 2.11.26 should immediately assess their configurations and apply necessary updates to safeguard against potential attacks.

Affected Version(s)

Cena Store <= 2.11.26

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.