CVE-2025-26760

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 22, 2025
CWE ID 98

Summary

CVE-2025-26760 is a filename manipulation vulnerability affecting the Wow-Company Calculator Builder from an unknown version up to 1.6.2. An attacker can exploit this PHP Remote File Inclusion (RFI) vulnerability by controlling the filename for an include or require statement, leading to local file inclusion and possible code execution. This issue could result in serious security implications if an attacker gains unauthorized access to sensitive data or executes malicious code on the affected system. PHP users are advised to update their Calculator Builder installation as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share