CVE-2025-23915
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 98
Summary
CVE-2025-23915 is a filename manipulation vulnerability affecting Roninwp FAT Event Lite, from an undisclosed version up to 1.1. An attacker can exploit this PHP Remote File Inclusion (RFI) issue to include local files on the vulnerable server, potentially leading to information disclosure or code execution. The vulnerability occurs due to the software's lack of proper control over filenames in include/require statements.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress