PHP Remote File Inclusion Vulnerability in StylemixThemes Consulting Elementor Widgets
CVE-2025-64360 
7.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 31 October 2025
What is CVE-2025-64360?
A vulnerability exists in the StylemixThemes Consulting Elementor Widgets plugin, allowing for PHP Local File Inclusion due to improper control over filename handling in include statements. This can enable an attacker to execute malicious PHP scripts on the server, leading to unauthorized access and potentially compromising sensitive data on affected installations up to version 1.4.2.
Affected Version(s)
Consulting Elementor Widgets <= n/a
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
 None
Availability:
 High
Attack Vector:
Network
Attack Complexity:
 Low
Privileges Required:
 None
User Interaction:
 None
Scope:
 Unchanged
Timeline
- Vulnerability published 
- Vulnerability Reserved 
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program