PHP Remote File Inclusion Vulnerability in thembay Fana Plugin
CVE-2025-49251
8.1HIGH
What is CVE-2025-49251?
A vulnerability exists in the thembay Fana plugin that permits PHP Local File Inclusion due to improper control of the filename for an include or require statement. This flaw could allow malicious actors to exploit the functionality of the plugin, potentially leading to unauthorized access and control over sensitive files on the web server. It's crucial for users of the affected versions to apply updates or take necessary precautions to safeguard their websites.
Affected Version(s)
Fana <= 1.1.28