Local File Inclusion Vulnerability in BuddyDev's MediaPress Plugin
CVE-2025-58608
7.5HIGH
What is CVE-2025-58608?
The MediaPress plugin by BuddyDev is susceptible to a Local File Inclusion vulnerability due to improper control of the filename in include or require statements. This flaw allows attackers to potentially execute unauthorized PHP code, leading to unauthorized access and manipulation of sensitive files on the server. This vulnerability affects versions of MediaPress from n/a through 1.5.9.1, highlighting the importance of applying security updates and best practices for PHP file inclusion handling.
Affected Version(s)
MediaPress <= 1.5.9.1