PHP Remote File Inclusion Vulnerability in Simple Payment Plugin by Ido Kobelkowsky
CVE-2025-62075
7.3HIGH
What is CVE-2025-62075?
A vulnerability allowing remote file inclusion in the Simple Payment plugin can lead to unauthorized access and potential compromise of the server. This flaw, found in versions up to 2.4.6 of the plugin, enables attackers to manipulate the PHP include or require statements, potentially executing arbitrary files and exposing sensitive data. Users are urged to update to secure versions and implement best practices to protect their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Simple Payment <= n/a
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien | Patchstack Bug Bounty Program