CVE-2025-30890

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 27, 2025
CWE ID 98

Summary

CVE-2025-30890 is a filename control vulnerability affecting the SuitePlugins Login Widget for Ultimate Member. This issue enables PHP Local File Inclusion, allowing attackers to gain unauthorized access to the system. The vulnerability lies in the way the plugin handles include/require statements, and it affects all versions from n/a to 1.1.2. Successful exploitation could result in unintended file execution or data disclosure, posing a significant risk to the security of the affected installations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share