CVE-2025-22305

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 7, 2025
CWE ID 98

Summary

CVE-2025-22305 is a newly identified vulnerability affecting WP OnlineSupport's Hero Banner Ultimate plugin. This issue involves improper control of filenames in PHP include/require statements, leading to a Local File Inclusion (LFI) vulnerability. Hackers can exploit this weakness to access and execute arbitrary local files on affected systems. The vulnerability has been present in Hero Banner Ultimate since its inception, and versions up to 1.4.2 are reportedly affected. It is crucial for users to update their plugins to the latest, secure versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share