CVE-2025-25122

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 3, 2025
CWE ID 35

Summary

CVE-2025-25122 is a newly discovered vulnerability affecting WizShop versions 3.0.2 and below. This issue involves a Path Traversal weakness, enabling an attacker to execute PHP Local File Inclusion. By manipulating the file path, unauthorized data access or potentially even code execution can occur, posing a significant security risk. It is crucial for users to update their WizShop installations to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share