CVE-2025-25122
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Mar 3, 2025
CWE ID 35
Summary
CVE-2025-25122 is a newly discovered vulnerability affecting WizShop versions 3.0.2 and below. This issue involves a Path Traversal weakness, enabling an attacker to execute PHP Local File Inclusion. By manipulating the file path, unauthorized data access or potentially even code execution can occur, posing a significant security risk. It is crucial for users to update their WizShop installations to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.