CVE-2025-26894
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 15, 2025
CWE ID 98
Summary
CVE-2025-26894 is a filename manipulation vulnerability affecting Coming Soon, Maintenance Mode versions 1.1.1 and below. The PHP Remote File Inclusion (RFI) flaw enables an attacker to include and execute arbitrary PHP files on the targeted system by exploiting the application's weak control over include/require statements. This issue might lead to serious consequences, including data theft, unauthorized access, or even system compromise. Users are advised to update their Coming Soon, Maintenance Mode installation as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.