PHP Remote File Inclusion Vulnerability in Ray Enterprise Translation by jbhovik
CVE-2025-60076

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 December 2025

What is CVE-2025-60076?

The Ray Enterprise Translation plugin by jbhovik contains a vulnerability that permits local file inclusion due to improper control of filenames in PHP include/require statements. This security flaw can allow unauthorized access to sensitive local files, leading to potential information disclosure or further attacks against the affected system. It impacts versions of the plugin up to and including 1.7.1, necessitating immediate attention from users to mitigate potential risks.

Affected Version(s)

Ray Enterprise Translation 0 <= 1.7.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien | Patchstack Bug Bounty Program
.