PHP Remote File Inclusion Vulnerability in Simple Payment Plugin by Ido Kobelkowsky
CVE-2025-62075
7.3HIGH
What is CVE-2025-62075?
A vulnerability allowing remote file inclusion in the Simple Payment plugin can lead to unauthorized access and potential compromise of the server. This flaw, found in versions up to 2.4.6 of the plugin, enables attackers to manipulate the PHP include or require statements, potentially executing arbitrary files and exposing sensitive data. Users are urged to update to secure versions and implement best practices to protect their applications.
Affected Version(s)
Simple Payment <= n/a
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien | Patchstack Bug Bounty Program