PHP Remote File Inclusion Vulnerability in Ghost Kit by nK
CVE-2025-53567
8.1HIGH
What is CVE-2025-53567?
The Ghost Kit plugin developed by nK is vulnerable to an improper control of filenames for include/require statements, allowing for PHP Local File Inclusion. This vulnerability could enable attackers to execute malicious scripts on the server by exploiting the plugin's functionality. Affected versions range from n/a to 3.4.1, and it is crucial for users to update to the latest version to protect their websites from potential security breaches and unauthorized access.
Affected Version(s)
Ghost Kit <= 3.4.1