CVE-2025-24733
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-24733 is a filename manipulation vulnerability affecting the AddonMaster Post Grid Master plugin for PHP. An attacker can exploit this issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, to include local files by manipulating the filename in an include/require statement. This flaw, which exists from version n/a up to 3.4.12, poses a significant risk for unauthorized file disclosure or code execution. Successful exploitation could lead to serious consequences, including data breaches or system compromise. It is recommended that affected users update their plugin to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress