PHP Remote File Inclusion Vulnerability in PublishPress Gutenberg Blocks
CVE-2025-48332
7.5HIGH
What is CVE-2025-48332?
A vulnerability exists in PublishPress Gutenberg Blocks that allows for PHP Local File Inclusion due to improper control of filename in include/require statements. This issue impacts versions from n/a to 3.3.1 and can lead to unauthorized access to local files on the server, potentially exposing sensitive information and compromising the integrity of the web application.
Affected Version(s)
Gutenberg Blocks <= 3.3.1