CVE-2025-30785
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-30785 is a newly disclosed vulnerability affecting WP Shuffle Subscribe to Download Lite, a plugin used for managing file downloads in WordPress. The issue stems from an improper control of filename for include/require statement in the plugin's PHP program, resulting in a Local File Inclusion (LFI) vulnerability. An attacker can exploit this weakness to access and read arbitrary local files on the affected system, potentially leading to data exposure or further system compromise. The vulnerability has been identified in versions 1.0 through 1.2.9 of the plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress