Local File Inclusion Vulnerability in BizCalendar Web Plugin for WordPress
CVE-2025-7650
7.5HIGH
What is CVE-2025-7650?
The BizCalendar Web Plugin for WordPress is susceptible to Local File Inclusion in all versions up to and including 1.1.0.50. This vulnerability allows authenticated users with Contributor-level permissions and above to include and execute arbitrary files on the server by exploiting the 'bizcalv' shortcode. Consequently, attackers can execute PHP code from these files, which may lead to bypassing access controls and accessing sensitive information, potentially compromising the entire WordPress environment.
Affected Version(s)
BizCalendar Web * <= 1.1.0.50