PHP Remote File Inclusion Vulnerability in RadiusTheme Widget for Google Reviews
CVE-2025-53565

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-53565?

The RadiusTheme Widget for Google Reviews is affected by a PHP Remote File Inclusion vulnerability that allows attackers to exploit improper control of filenames used in include or require statements. This flaw opens the door for local file inclusion, potentially allowing unauthorized access to sensitive files on the server. The issue impacts Widget for Google Reviews versions from n/a up to 1.0.15, posing a significant risk to IT security and website integrity.

Affected Version(s)

Widget for Google Reviews <= 1.0.15

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k (Patchstack Alliance)
.