CVE-2025-27011

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 98

Summary

CVE-2025-27011 is a Filename Validation Error in the magepeopleteam Booking and Rental Manager PHP application. This vulnerability, classified as a PHP Remote File Inclusion (RFI), permits an attacker to include local files by manipulating the filename for an include or require statement. This issue poses a security risk, as an attacker could potentially access sensitive information or execute malicious code. The vulnerability affects versions of the Booking and Rental Manager software from n/a through 2.2.8. It is recommended that affected users upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Booking And Rental Manager Plugin

Affected Vendors

  • WordPress