Local File Inclusion Vulnerability in BuddyDev's MediaPress Plugin
CVE-2025-58608

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2025

What is CVE-2025-58608?

The MediaPress plugin by BuddyDev is susceptible to a Local File Inclusion vulnerability due to improper control of the filename in include or require statements. This flaw allows attackers to potentially execute unauthorized PHP code, leading to unauthorized access and manipulation of sensitive files on the server. This vulnerability affects versions of MediaPress from n/a through 1.5.9.1, highlighting the importance of applying security updates and best practices for PHP file inclusion handling.

Affected Version(s)

MediaPress <= 1.5.9.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zaim (Patchstack Alliance)
.