CVE-2025-22311

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 21, 2025
CWE ID 98

Summary

CVE-2025-22311 is a filename vulnerability affecting NotFound Private Messages for UserPro, from version n/a through 4.10.0. An attacker can exploit this PHP Remote File Inclusion (RFI) issue by improperly controlling the filename included in a statement. The vulnerability allows an attacker to execute arbitrary code on the affected system, posing a significant risk to data confidentiality and integrity. Users of NotFound Private Messages for UserPro are advised to update to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share