Local File Inclusion Vulnerability in Immocaster WordPress Plugin by Hinnerk Altenburg
CVE-2025-60190
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 November 2025
What is CVE-2025-60190?
The Immocaster WordPress Plugin, developed by Hinnerk Altenburg, is susceptible to a Local File Inclusion (LFI) vulnerability due to improper control in the filename parameter of include/requires statements in PHP. This flaw can potentially allow attackers to access files on the server, leading to unauthorized data exposure or system compromise. Affected versions include Immocaster up to and including 1.3.6. Website administrators are encouraged to update to a patched version to eliminate this security risk.
Affected Version(s)
Immocaster WordPress Plugin <= n/a