PHP Remote File Inclusion Vulnerability in Premmerce User Roles by Premmerce
CVE-2025-60193

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-60193?

The vulnerability in Premmerce User Roles exposes systems to PHP Local File Inclusion via improper control of filenames in include or require statements. This flaw allows attackers to potentially execute arbitrary PHP code, compromising the integrity and security of the application. Versions of Premmerce User Roles up to 1.0.13 are affected, emphasizing the need for immediate attention to patch and secure your installations.

Affected Version(s)

Premmerce User Roles <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVT-tholv2k | Patchstack Bug Bounty Program
.