PHP Remote File Inclusion Vulnerability in StylemixThemes Consulting Elementor Widgets
CVE-2025-64360

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
31 October 2025

What is CVE-2025-64360?

A vulnerability exists in the StylemixThemes Consulting Elementor Widgets plugin, allowing for PHP Local File Inclusion due to improper control over filename handling in include statements. This can enable an attacker to execute malicious PHP scripts on the server, leading to unauthorized access and potentially compromising sensitive data on affected installations up to version 1.4.2.

Affected Version(s)

Consulting Elementor Widgets <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.
CVE-2025-64360 : PHP Remote File Inclusion Vulnerability in StylemixThemes Consulting Elementor Widgets