Local File Inclusion Vulnerability in Dream-Theme The7 Elements Plugin
CVE-2025-63076
7.5HIGH
What is CVE-2025-63076?
The The7 Elements plugin by Dream-Theme is susceptible to a local file inclusion vulnerability, primarily due to improper control over file paths within its PHP code. This flaw enables malicious actors to exploit the plugin, allowing them to include arbitrary local files, potentially leading to unauthorized access and manipulation of sensitive data. Users of The7 Elements version 2.7.11 and prior are particularly at risk, and it is crucial for them to update their plugin to mitigate the associated security threats.
Affected Version(s)
The7 Elements <= n/a
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program