CVE-2025-30891
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-30891 is a filename manipulation vulnerability affecting the magepeopleteam WpTravelly plugin for WordPress. This issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, allows an attacker to include local files on the vulnerable system by exploiting improper control over filenames in include/require statements. The weakness impacts versions of WpTravelly from n/a through 1.8.7. Successful exploitation of this vulnerability could lead to information disclosure or even code execution, potentially resulting in significant security risks and potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Wptravelly Plugin
Affected Vendors
- WordPress