Local File Inclusion Vulnerability in Alloggio - Hotel Booking by Edge-Themes
CVE-2025-64287

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-64287?

The Alloggio - Hotel Booking theme by Edge-Themes is vulnerable to local file inclusion due to improper control of filenames used in PHP include or require statements. This flaw enables attackers to execute malicious scripts and access sensitive files on the server, potentially leading to compromising the integrity of the affected system. The theme version up to 1.8 is impacted, highlighting the importance of immediate updates and security measures to safeguard your website.

Affected Version(s)

Alloggio - Hotel Booking <= n/a

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.
CVE-2025-64287 : Local File Inclusion Vulnerability in Alloggio - Hotel Booking by Edge-Themes