Local File Inclusion Vulnerability in Easy Pricing Table WP by Pluginwale
CVE-2025-53450

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-53450?

A vulnerability exists in the Easy Pricing Table WP plugin by Pluginwale that allows local file inclusion via improperly controlled filename parameters. When exploited, this flaw can permit attackers to gain access to sensitive files on the server, potentially leading to further exposure of the application and the environment it operates in. This affects versions from not available through 1.1.3.

Affected Version(s)

Easy Pricing Table WP <= 1.1.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.