CVE-2025-30890
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 27, 2025
CWE ID 98
Summary
CVE-2025-30890 is a filename control vulnerability affecting the SuitePlugins Login Widget for Ultimate Member. This issue enables PHP Local File Inclusion, allowing attackers to gain unauthorized access to the system. The vulnerability lies in the way the plugin handles include/require statements, and it affects all versions from n/a to 1.1.2. Successful exploitation could result in unintended file execution or data disclosure, posing a significant risk to the security of the affected installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress