PHP Remote File Inclusion Vulnerability in Simple Contact Forms by owenr88
CVE-2025-60197
8.2HIGH
What is CVE-2025-60197?
A vulnerability in the Simple Contact Forms plugin by owenr88 allows attackers to exploit improperly controlled filenames for include or require statements, leading to PHP Local File Inclusion (LFI). This weakness can enable unauthorized access to sensitive files on the server, potentially compromising the entire application and its underlying infrastructure. It is imperative for users of affected versions (up to 1.6.4) to apply necessary updates or patches to mitigate this vulnerability.
Affected Version(s)
Simple Contact Forms <= n/a