Local File Inclusion Vulnerability in WP Abstracts Manuscripts Manager by Kevon Adonis
CVE-2025-48338

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-48338?

The WP Abstracts Manuscripts Manager plugin, developed by Kevon Adonis, contains a vulnerability that allows improper control of filenames during include/require operations. This PHP Remote File Inclusion issue permits potential attackers to leverage local files on the server, potentially leading to unauthorized access or code execution. This affects versions of the plugin up to and including 2.7.4, posing a significant risk to websites utilizing this plugin if not patched.

Affected Version(s)

WP Abstracts <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut (Patchstack Alliance)
.