CVE-2025-22311
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 21, 2025
CWE ID 98
Summary
CVE-2025-22311 is a filename vulnerability affecting NotFound Private Messages for UserPro, from version n/a through 4.10.0. An attacker can exploit this PHP Remote File Inclusion (RFI) issue by improperly controlling the filename included in a statement. The vulnerability allows an attacker to execute arbitrary code on the affected system, posing a significant risk to data confidentiality and integrity. Users of NotFound Private Messages for UserPro are advised to update to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.