Local File Inclusion Vulnerability in Immocaster WordPress Plugin by Hinnerk Altenburg
CVE-2025-60190
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 November 2025
What is CVE-2025-60190?
The Immocaster WordPress Plugin, developed by Hinnerk Altenburg, is susceptible to a Local File Inclusion (LFI) vulnerability due to improper control in the filename parameter of include/requires statements in PHP. This flaw can potentially allow attackers to access files on the server, leading to unauthorized data exposure or system compromise. Affected versions include Immocaster up to and including 1.3.6. Website administrators are encouraged to update to a patched version to eliminate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Immocaster WordPress Plugin <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved