PHP Remote File Inclusion Vulnerability in Ray Enterprise Translation by jbhovik
CVE-2025-60076
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-60076?
The Ray Enterprise Translation plugin by jbhovik contains a vulnerability that permits local file inclusion due to improper control of filenames in PHP include/require statements. This security flaw can allow unauthorized access to sensitive local files, leading to potential information disclosure or further attacks against the affected system. It impacts versions of the plugin up to and including 1.7.1, necessitating immediate attention from users to mitigate potential risks.
Affected Version(s)
Ray Enterprise Translation 0 <= 1.7.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien | Patchstack Bug Bounty Program