Local File Inclusion Vulnerability in AnyComment by Alexander
CVE-2025-60240

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-60240?

The AnyComment plugin by Alexander is susceptible to a Local File Inclusion vulnerability due to improper handling of filename for PHP include/require statements. This flaw allows attackers to execute arbitrary code within the server environment, posing a severe risk to application integrity and user data security. The issue affects versions of AnyComment from an unspecified version up to and including 0.3.6. Users are advised to evaluate their installations and consider patching or upgrading to secure their applications.

Affected Version(s)

AnyComment <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien | Patchstack Bug Bounty Program
.