CVE-2025-1771

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 15, 2025
Updated: Mar 28, 2025
CWE ID 98

Summary

CVE-2025-1771 is a local file inclusion vulnerability affecting the Traveler theme for WordPress. Versions up to 3.1.8 are impacted, allowing unauthenticated attackers to include and execute arbitrary files on the server through the 'hotel_alone_load_more_post' function's 'style' parameter. This vulnerability can be exploited to bypass access controls, obtain sensitive data, or execute any PHP code present in the included files. Successful exploitation could result in significant security risks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share