Remote File Inclusion Vulnerability in Tribulant Software Newsletters
CVE-2025-54034

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-54034?

A vulnerability exists in Tribulant Software Newsletters, allowing for PHP Local File Inclusion due to improper control of filenames in Include/Require statements. This can enable attackers to execute malicious scripts by including arbitrary local files in the application. The affected versions include Newsletters from 'n/a' through 4.10. It is crucial for users to review their current software versions and apply necessary updates to mitigate any risks.

Affected Version(s)

Newsletters <= 4.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.