CVE-2025-26894

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 15, 2025
CWE ID 98

Summary

CVE-2025-26894 is a filename manipulation vulnerability affecting Coming Soon, Maintenance Mode versions 1.1.1 and below. The PHP Remote File Inclusion (RFI) flaw enables an attacker to include and execute arbitrary PHP files on the targeted system by exploiting the application's weak control over include/require statements. This issue might lead to serious consequences, including data theft, unauthorized access, or even system compromise. Users are advised to update their Coming Soon, Maintenance Mode installation as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share