PHP Local File Inclusion Vulnerability in Roxnor FundEngine
CVE-2025-48302

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-48302?

The Roxnor FundEngine product is affected by a vulnerability that allows for PHP Local File Inclusion, stemming from improper handling of filenames in include or require statements. This flaw could potentially allow an attacker to include local PHP files, leading to unauthorized file access and execution. The issue impacts all versions up to 1.7.4, rendering those systems vulnerable to exploitation.

Affected Version(s)

FundEngine 0 <= 1.7.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.